« Repeat After Me: Lack of _Output Encoding_ Causes XSS Vulnerabilities | Main | Digg Vulnerable to XSS »

Papa John’s Pizza’s Corporate E-mails Still Exposed (thanks Google)

According to this posting on the Full Disclosure mailing list, Papa John’s Pizza’s web-based e-mail system was not password protected for a while. They have since fixed the problem, but Google currently has the information in its cache. The following Google query will let you see these e-mails (click on the ‘Cached’ links):

site:webmail02.papajohns.com PJFS

Now try the following query to find the more interesting e-mails:

site:webmail02.papajohns.com PJFS password

This brings me back to my previous article on using Google to find vulnerabilities. It isn’t enough for Papa John’s Pizza to fix the issue, for the exposed information is still available to the world via Google’s cache. I’m hoping they will contact Google and request for this information to be removed, but this may take a while to process.

Update: Google cache no longer contains the above information.

About

This page contains a single entry from the blog posted on November 8, 2005 2:48 PM.

The previous post in this blog was Repeat After Me: Lack of _Output Encoding_ Causes XSS Vulnerabilities.

The next post in this blog is Digg Vulnerable to XSS.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.35