Re: CubeCart 5.0.7 and lower versions | Insecure Backup File Handling

2013-01-01 Thread YGN Ethical Hacker Group
5.x only On Sat, Dec 29, 2012 at 11:02 AM, Sean Jenkins s...@bluehost.com wrote: Is it known if this exploit affects CubeCart versions 3.x and/or 4.x, or just 5.0.[0..6]? Sean Jenkins Sr. System Administrator On 12/28/2012 8:13 AM, YGN Ethical Hacker Group wrote: 1. OVERVIEW CubeCart

Re: CubeCart 5.0.7 and lower versions | Insecure Backup File Handling

2012-12-31 Thread Sean Jenkins
Is it known if this exploit affects CubeCart versions 3.x and/or 4.x, or just 5.0.[0..6]? Sean Jenkins Sr. System Administrator On 12/28/2012 8:13 AM, YGN Ethical Hacker Group wrote: 1. OVERVIEW CubeCart 5.0.7 and lower versions are vulnerable to Insecure Backup File Handling which leads to

CubeCart 5.0.7 and lower versions | Insecure Backup File Handling

2012-12-28 Thread YGN Ethical Hacker Group
1. OVERVIEW CubeCart 5.0.7 and lower versions are vulnerable to Insecure Backup File Handling which leads to the disclosure of the application configuration file. 2. BACKGROUND CubeCart is an out of the box ecommerce shopping cart software solution which has been written to run on servers that