CyberCash has a flaw that causes all credit card information processed to be logged to a file that is world readable. This flaw occurs on default installations due to the DEBUG flag being set to '0' and ignoring alternate settings.
Classification
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution
Upgrade to version 3.0 or higher, as it has been reported to fix this vulnerability.