Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ProfitCode Software PayProCart Directory Traversal Vulnerability

An exploit is not required.

The following proof of concept can allow an attacker to gain administrative access to the application:

http://www.example.com/adminshop/index.php?proMod=index&amp%3bftoedit=..%2fshopincs%2fmaintopENG







 

Privacy Statement
Copyright 2008, SecurityFocus