HTTP: cart32 Admin Password Change

This signature detects attempts to exploit McMurtrey/Whitaker & Associates Cart32 shopping cart. Attackers can change the administrator password to an arbitrary value without prior knowledge of the original password.

Extended Description

Within cart32.exe, entering any password by way of http://target/scripts/cart32.exe/cart32clientlist, a remote user could obtain vital client information such as username, password, credit card numbers, and other crucial details. Passwords will appear encrypted, however they can be used in conjunction with specific URL requests which can be used to execute arbitrary commands. In addition, by accessing http://target/scripts/c32web.exe/ChangeAdminPassword, a remote user is able to change the administrative password without prior knowledge of the previous password.

Affected Products

Mcmurtrey/whitaker_&_associates cart32

References

BugTraq: 1153

CVE: CVE-2000-0136

Short Name
HTTP:PKG:CART32-ADM-PW-CHG
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Admin CVE-2000-0136 Change Password bid:1153 cart32
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Mcmurtrey/whitaker_&_associates

CVSS Score

7.5

Found a potential security threat?