Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.16388
Kategorie:Web application abuses
Titel:Credit Card Data Disclosure in CitrusDB
Zusammenfassung:CitrusDB uses a textfile to temporarily store credit card information.;; This textfile is located in the web tree via a static URL and thus accessible to third parties.; It also isn't deleted after processing resulting in a big window of opportunity for an attacker.
Beschreibung:Summary:
CitrusDB uses a textfile to temporarily store credit card information.

This textfile is located in the web tree via a static URL and thus accessible to third parties.
It also isn't deleted after processing resulting in a big window of opportunity for an attacker.

Solution:
Update to CitrusDB version 0.3.6 or higher and set the
option '$path_to_ccfile' in the configuration to a path not accessible via HTTP.

Workaround : Either deny access to the file using access restriction
features of the remote webserver or change CitrusDB to use a file
outside the document root and not accessible via HTTP.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: BugTraq ID: 12402
Common Vulnerability Exposure (CVE) ID: CVE-2005-0229
http://www.securityfocus.com/bid/12402
http://marc.info/?l=full-disclosure&m=110824766519417&w=2
http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt
http://securitytracker.com/id?1013040
XForce ISS Database: citrus-information-disclosure(19145)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19145
CopyrightCopyright (C) 2005 Noam Rathaus

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.