|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
ibuyspystore.com contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by a lack of authorization when viewing existing orders, which will disclose order information resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
OSVDB:
Concern
|
|
Technical |
This is a demonstration site, which encourages developers to use the sample code provided. The concern related to this flaw is that developers ought not to learn to use insecure code.
|
|
Solution |
Do not view and copy this code for any software projects.
|
|
Products |
|
ibuyspystore.com
 |
All Versions |
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|