Backup Source Code Detected
Medium
S
Starbucks
Submitted None
Actions:
Reported by
linkks
Vulnerability Details
Technical details and impact analysis
Impact
Depending on the nature of the source code disclosed, an attacker can mount one or more of the following types of attacks:•Access the database or other data resources. With the privileges of the account obtained, attempt to read, update or delete arbitrary data from the database.
•Access password protected administrative mechanisms such as "dashboard", "management console" and "admin panel" potentially leading to full control of the application.
•Develop further attacks by investigating the source code for input validation errors and logic vulnerabilities.
Actions to Take
Remove all temporary and backup files.
Required Skills for Successful Exploitation
This is dependent on the information obtained from source code. Uncovering these forms of vulnerabilities does not require high levels of skills. However, a highly skilled attacker could leverage this form of vulnerability to obtain account information for databases or administrative panels, ultimately leading to control of the application or even the host the application resides on.
## Impact
GET /howto/store/order.html~ HTTP/1.1
Host: www.starbucks.co.jp
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-us,en;q=0.5
Cache-Control: no-cache
Cookie: PHPSESSID=██████; registerParams[0]=card; registerParams[1]=https%3A%2F%2Fcard.starbucks.co.jp%2Fmystarbucks%2Fcard%2FregisterMsc%2F
Referer: http://www.starbucks.co.jp/howto/store/order.html~
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36
<?php
include_once($_SERVER['DOCUMENT_ROOT']."/config.inc.php");
// ページプãƒãƒ‘ティè¨å®š
$pageProperties['title'] = "How to オーダー";
$pageProperties['description'] = "スターãƒãƒƒã‚¯ã‚¹ã§ã¯ãŠå®¢æ§˜ã®ã”希望ã«å¿œãˆã‚‰ã‚Œã‚‹ã‚ˆã†ã€æ§˜ã€…ãªã‚ªãƒ¼ãƒ€ãƒ¼ã‚·ã‚¹ãƒ†ãƒ ã‚’ã”用æ„ã—ã¦ã„ã¾ã™ã€‚";
$pageProperties['keyword'] = _BASE_META_KEYWORD_.",ä½¿ã„æ–¹,how,オーダー,注文,order,ビãƒãƒ¬ãƒƒã‚¸,beverage,メニュー,menu,サイズ,size";
$pageProperties['ogImage'] = "http://www.starbucks.co.jp/images/og/howto-order.jpg";
?>
<!DOCTYPE html>
<html lang="ja">
<head>
<meta charset="utf-8">
<title><?php echo $pageProperties['title']; ?>|スターãƒãƒƒã‚¯ã‚¹ コーヒー ジャパン</title>
<?php include(_SB_DIR_INCLUDE_."/common/meta.html"); ?>
<link type="text/css" rel="stylesheet" href="/common/css/contents.css" media="screen,print">
<link type="text/css" rel="stylesheet" href="/howto/store/css/index.css" media="screen,print">
<link type="text/css" rel="stylesheet" href="/howto/css/howto.css" media="screen,print">
<?php include(_SB_DIR_INCLUDE_."/common/css-pc.html"); ?>
<?php include(_SB_DIR_INCLUDE_."/common/js-old.html"); ?>
</head>
<body>
<noscript>
<p class="noscript">当サイトをã”覧ã„ãŸã ãã«ã¯ãƒ–ラウザã®è¨å®šã§<strong>JavaScriptを有効ã«è¨å®š</strong>ã™ã‚‹å¿…è¦ãŒã”ã–ã„ã¾ã™ã€‚</p>
</noscript>
<?php include(_SB_DIR_INCLUDE_."/common/welcome.html"); ?>
<?php include(_SB_DIR_INCLUDE_."/common/header.html"); ?>
<?php include(_SB_DIR_INCLUDE_."/common/title-scroll.html"); ?>
<div class="mainContents static migration withLocalNav">
<article>
<header class="local">
<h2><?php echo $pageProperties['title']; ?></h2>
<?php include(_SB_DIR_INCLUDE_."/common/sns.html"); ?>
<ul class="backLinks">
<li><a href="/howto/">
<div><p>How to STARBUCKS</p></div>
</a></li>
</ul>
</header>
<div class="mainArea typeWithSideA">
<div id="contentsMainIn" class="newContents">
<div class="container">
<h3 class="order mT0">1.ビãƒãƒ¬ãƒƒã‚¸ã‚’é¸ã³ã¾ã—ょã†ã€‚</h3>
<p>コーヒーやフラペãƒãƒ¼ãƒŽã®ä»–ã‚‚ã€ã‚³ã‚³ã‚¢ã‚„ジュースもã”用æ„ã—ã¦ã„ã¾ã™ã€‚</p>
<ul class="listInline becerage mB35">
<li><img src="/howto/store/images/img-order-coffee.jpg" width="159" height="218" alt="コーヒー 高å“質ã®ã‚¢ãƒ©ãƒ“カ種コーヒー豆を使用ã—ãŸå®šç•ªãƒ“ãƒãƒ¬ãƒƒã‚¸ã€‚"></li>
<li><img src="/howto/store/images/img-order-espresso.jpg" width="160" height="218" alt="エスプレッソ ビãƒãƒ¬ãƒƒã‚¸ å®Œç’§ã«æŠ½å‡ºã•れãŸã‚¨ã‚¹ãƒ—レッソを使用ã—ãŸãƒ“ãƒãƒ¬ãƒƒã‚¸ã€‚"></li>
<li><img src="/howto/store/images/img-order-frappuccino.jpg" width="159" height="218" alt="フラペãƒãƒ¼ãƒŽÂ® 一年を通ã—ã¦ç¾Žå‘³ã—ãæ¥½ã—ã‚ã‚‹ã€ãƒ•ãƒãƒ¼ã‚ºãƒ³ãƒ“ãƒãƒ¬ãƒƒã‚¸ã€‚"></li>
<li class="lastChild"><img src="/howto/store/images/img-order-tea.jpg" width="155" height="218" alt="ティービãƒãƒ¬ãƒƒã‚¸ãƒ»ãã®ä»– ティーã€ã‚³ã‚³ã‚¢ã€100%ジュースãªã©ã‚‚ã‚りã¾ã™ã€‚"></li>
</ul>
<div class="listWithTypeA">
<p class="mB15">定番ビãƒãƒ¬ãƒƒã‚¸ã®ã»ã‹ã«ã‚‚ã€å£ç¯€ã«åˆã‚ã›ãŸãŠã™ã™ã‚ã®ãƒ“ãƒãƒ¬ãƒƒã‚¸ã‚‚ã”用æ„ã—ã¦ã„ã¾ã™ã€‚</p>
<ul class="links mB30">
<li><a href="/beverage/">ビãƒãƒ¬ãƒƒã‚¸ãƒ¡ãƒ‹ãƒ¥ãƒ¼ä¸€è¦§</a></li>
</ul>
<p class="lightFontS mB0">My Starbucks会員ã®çš†æ§˜ã«ã¯ã€å£ç¯€é™å®šã®ãƒ“ãƒãƒ¬ãƒƒã‚¸ã‚’ã„ã¡æ—©ã確èªã§ãる先行告知を行ã£ã¦ãŠã‚Šã¾ã™ã€‚</p>
<p class="itemNotes mB15">登録ã¯ç„¡æ–™ã§ã™</p>
<ul class="links">
<li><a href="/register/mystarbucks/input/#input">My Starbucks会員登録</a></li>
</ul>
<!-- /.listWithTypeA --></div>
<!-- /.container --></div>
<div class="container">
<h3 class="order">2.サイズもã„ã‚ã„ã‚。</h3>
<p>飲ã¿ãŸã„é‡ã‚’飲ã¿ãŸã„ã ã‘。サイズã¯4種類ã‹ã‚‰ãŠé¸ã³ãã ã•ã„。</p>
<ul class="listInline size">
<li><img src="/howto/store/images/index-img-short.jpg" width="155" height="205" alt="ショート Short(240ml)"></li>
<li><img src="/howto/store/images/index-img-tall.jpg" width="155" height="205" alt="トール Tall(350ml)"></li>
<li><img src="/howto/store/images/index-img-grande.jpg" width="155" height="205" alt="グランデ Grande(470ml)"></li>
<li class="lastChild"><img src="/howto/store/images/index-img-venti.jpg" width="155" height="205" alt="ベンティ Venti®(590ml)"></li>
</ul>
<ul class="notes light fontS">
<li><span class="mark">※</span>å„サイズã®å®¹é‡ã¯ã€ç›®å®‰ã§ã™ã€‚</li>
<li><span class="mark">※</span>アイスドリンクã®ã‚·ãƒ§ãƒ¼ãƒˆã‚µã‚¤ã‚ºã¯300mlã§ã™ã€‚</li>
</ul>
<!-- /.container --></div>
<div class="container last">
<h3 class="order">3.ビãƒãƒ¬ãƒƒã‚¸ã‚’自分好ã¿ã®å‘³ã‚ã„ã«ã€‚</h3>
<p>ビãƒãƒ¬ãƒƒã‚¸ã¯ãŠå¥½ã¿ã«åˆã‚ã›ã¦ã€è‡ªç”±ã«ã‚«ã‚¹ã‚¿ãƒžã‚¤ã‚ºã™ã‚‹ã“ã¨ãŒã§ãã¾ã™ã€‚</p>
<div class="col">
<div class="col2">
<h4 class="order">レジ㧠<span>at Cash register</span></h4>
<p class="mB20"><img src="/howto/store/images/img-order-arrange.jpg" alt="ミルクをé¸ã‚“ã り ã‚·ãƒãƒƒãƒ—ã‚„ã‚½ãƒ¼ã‚¹ã‚’è¿½åŠ ã—ãŸã‚Š ã‚¨ã‚¹ãƒ—ãƒ¬ãƒƒã‚½ã‚·ãƒ§ãƒƒãƒˆã‚’è¿½åŠ ã—ã¦é¢¨å‘³ã‚’より深ã" width="318" height="154"></p>
<p class="tasteTxt mB0">オーダー時ã«ã€ãƒãƒªã‚¹ã‚¿ã«ãŠå°‹ããã ã•ã„。<br>
ãŠå¥½ã¿ã®å‘³ã‚’見ã¤ã‘ã‚‹ãŠæ‰‹ä¼ã„ã‚’ã•ã›ã¦ã„ãŸã ãã¾ã™ã€‚<br>
自分ã«ã´ã£ãŸã‚Šã®å‘³ã«å‡ºä¼šãˆã‚‹ã‹ã‚‚ã—れã¾ã›ã‚“。</p>
<!-- /.col2 --></div>
<div class="col2">
<h4 class="order">コンディメントãƒãƒ¼ã§ <span>at Condiment bar</span></h4>
<p class="mB20"><img src="/howto/store/images/img-order-bar.jpg" alt="" width="318" height="154"></p>
<p class="tasteTxt mB0">コンディメントãƒãƒ¼ã§ãŠå¥½ã¿ã®å‘³ã‚ã„ã«ã€‚<br>
コーヒーや紅茶ã«åŠ ãˆã‚‹ãƒŸãƒ«ã‚¯ã¯2種類。ãŠç ‚ç³–ã¯3種類。香り豊ã‹ã«ãªã‚‹ãƒ‘ウダーãªã©ã‚‚ã”用æ„ã—ã¦ã„ã¾ã™ã€‚</p>
<!-- /.col2 --></div>
<!-- /.col --></div>
<div class="withImgCol listWithTypeB mB45">
<ul class="btns row imgR mT3">
<li><a href="/howto/customize/index.html">How to カスタマイズ</a></li>
</ul>
<p class="txtL">カスタマイズã«ã¤ã„ã¦è©³ã—ãã¯ã“ã¡ã‚‰ã§ã€‚</p>
<!-- /.withImgCol.listWithTypeB.mB45 --></div>
<div class="arrangeBorderWrap">
<div class="arrangeBorder pT30 pB10">
<div class="withImgCol">
<p class="imgL"><img src="/howto/store/images/img-order-lid.jpg" alt="" width="160" height="97"></p>
<div class="txtR">
<h4 class="order">ã“ã®ãƒ•ã‚¿ã€å–らãšã«é£²ã‚“ã§ã¿ã¦ã€‚</h4>
<p>æ©ããªãŒã‚‰ã‚³ãƒ¼ãƒ’ーを楽ã—ã‚“ã ã‚Šã€æ¸©ã‹ãä¿ã¤åŠ¹æžœã¯ã‚‚ã¡ã‚ã‚“ã€<br>
ã“ã®ãƒ•ã‚¿ã«é–‹ã„ãŸå°ã•ãªé£²ã¿å£ã‹ã‚‰ç›´æŽ¥é£²ã‚€ã¨ã€ãƒ•ォームミルクやホイップクリームãŒç¨‹ã‚ˆãæ··ã–りåˆã„ã€æœ€å¾Œã¾ã§ãŠã„ã—ã味ã‚ãˆã¾ã™ã€‚ãœã²ãŠè©¦ã—ãã ã•ã„。</p>
<!-- /.txtR --></div>
<!-- /.withImgCol --></div>
<!-- /.arrangeBorder.pT30.pB10 --></div>
<div class="arrangeBorder last pT30">
<div class="withImgCol">
<p class="imgL"><img src="/howto/store/images/img-order-bring.jpg" alt="" width="160" height="119"></p>
<div class="txtR">
<h4 class="order">Bring My Cup</h4>
<p class="mB15">ドリンクをã”購入ã®éš›ã€ã”自分ã®ã‚¿ãƒ³ãƒ–ãƒ©ãƒ¼ã‚„ãƒžã‚°ã‚«ãƒƒãƒ—ã‚’ãŠæŒã¡ã„ãŸã ãã¨ã€<br>
資æºã®ç¯€ç´„ã«ã”å”力ã„ãŸã ã„ãŸãŠç¤¼ã¨ã—ã¦ã€ç¨ŽæŠœæœ¬ä½“ä¾¡æ ¼ã‹ã‚‰20円値引ã—ã¾ã™ã€‚<br>
<ul class="links mB30">
<li><a href="http://www.starbucks.co.jp/csr/environment/green_stores.html">スターãƒãƒƒã‚¯ã‚¹ç’°å¢ƒã¸ã®å–り組ã¿</a></li>
</ul>
<p class="txtR">ãŠæ°—ã«å…¥ã‚Šã®ãƒ‰ãƒªãƒ³ã‚¯ã‚’ã€ãŠæ°—ã«å…¥ã‚Šã®ã‚¿ãƒ³ãƒ–ラーã«å…¥ã‚Œã¦ã€‚<br>
ä¿æ¸©æ€§ã«å„ªã‚ŒãŸã‚¿ãƒ³ãƒ–ラーãªã‚‰ã€å¥½ããªã¨ãã«å¥½ããªå ´æ‰€ã§ãŠã„ã—ã味ã‚ãˆã¾ã™ã€‚</p>
<!-- /.txtR --></div>
<!-- /.withImgCol --></div>
<!-- /.arrangeBorder.last.pT30 --></div>
<!-- /.arrangeBorderWrap --></div>
<!-- /.container.last --></div>
<!-- /.newContents --></div>
<ul class="backLinks">
<li><a href="/howto/">
<div><p>How to STARBUCKS</p></div>
</a></li>
</ul>
<!-- /.mainArea.typeWithSideA --></div>
<nav class="localNav">
<div class="sideBar">
<ul class="backLinks">
<li><a href="/howto/">How to STARBUCKS</a></li>
</ul>
<ul class="navList">
<li class="is-located">
<p>ビãƒãƒ¬ãƒƒã‚¸ã‚’é¸ã¶<span>How to オーダー</span></p>
</li>
<li><a href="/howto/customize/">
<p>カスタマイズã«ãƒˆãƒ©ã‚¤<span>How to カスタマイズ</span></p></a></li>
<li class="linkParent">
<p>ã‚¹ãƒžãƒ¼ãƒˆã«æ¥½ã—ã‚€</p>
</li>
<li class="lower"><a href="/howto/store/tumbler.html">
<p><span>タンブラー</span></p></a></li>
<li class="lower"><a href="/howto/card/">
<p><span>スターãƒãƒƒã‚¯ã‚¹ カード</span></p></a></li>
<li><a href="/howto/food/">
<p>フードã¨ã‚³ãƒ¼ãƒ’ーを楽ã—ã‚€</p></a></li>
<li><a href="/customize/">
<p>ãŠæ°—ã«å…¥ã‚Šã®ä¸€æ¯ã‚’ã•ãŒã™</p></a></li>
<li><a href="/howto/coffee/">
<p>è‡ªå®…ã§æ¥½ã—ã‚€<span>at Home</span></p></a></li>
<li class="lower"><a href="/howto/coffee/beans.html">
<p><span>コーヒー豆をé¸ã¶</span></p></a></li>
<li class="lower"><a href="/howto/coffee/passport.html">
<p><span>コーヒーパスãƒãƒ¼ãƒˆï¼†ãƒ“ーンズカード</span></p></a></li>
<li class="lower"><a href="/howto/coffee/skill.html">
<p><span>ãŠã„ã—ã„コーヒーをã„れるコツ</span></p></a></li>
<li class="lower"><a href="/howto/coffee/seminar-kigu.html">
<p><span>コーヒーセミナー/コーヒー器具</span></p></a></li>
<li><a href="/howto/office/">
<p>ã‚ªãƒ•ã‚£ã‚¹ã§æ¥½ã—ã‚€<span>at Office</span></p></a></li>
<li><a href="/howto/mystarbucks/">
<p>My Starbucksã§æ¥½ã—ã‚€<span>会員登録</span></p></a></li>
<li><a href="/howto/index.html#andMore">
<p>便利ãªã‚µãƒ¼ãƒ“ス</p></a></li>
</ul>
<!-- /.sideBar --></div>
</nav>
<?php include(_SB_DIR_INCLUDE_."/common/sns-footer.html"); ?>
</article>
<!-- /.mainContents.static.migration.withLocalNav --></div>
<?php include(_SB_DIR_INCLUDE_."/common/footer.html"); ?>
<?php include(_SB_DIR_INCLUDE_."/common/nav-os.html"); ?>
</body>
</html>
Report Details
Additional information and metadata
State
Closed
Substate
Resolved