A few hundreds of their customers remain exposed as a result of the attack

Nov 14, 2011 08:09 GMT  ·  By

The website of Zapateria Orinoco, a Venezuelan shoe retailer, was hacked on November 12 by a hacker that calls himself @n4n0Cynet.

DataBreaches informs that 487 sets of credentials were leaked on Pastebin, including answers to security questions.

More unfortunate is that the usernames and passwords of two of the website's administrators were also leaked as a result of the breach.

There is no precise information on how the attacker managed to penetrate the site's defences, but it's very likely that he took advantage of a cross site scripting or an SQL injection vulnerability.

The location is currently online and hopefully its administrators alerted all their customers to make sure none of them get affected by the incident. Also, hopefully, they patched the holes that allowed for the attack to take place in the first place.