|
Agora.CGI Debug Mode Path Disclosure Vulnerability
Agora.cgi is a freely available, open source shopping cart system. When debug mode is enabled, it is possible for a remote attacker to display the absolute path to the directory that the agora.cgi script is stored in. This is possible by making a web request for a non-existent .html file. The remote attacker may potentially use the disclosed information to aid in further "intelligent" attacks against the host running the vulnerable software. |
|
|
Privacy Statement |