Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Agora.CGI Debug Mode Path Disclosure Vulnerability

Agora.cgi is a freely available, open source shopping cart system.

When debug mode is enabled, it is possible for a remote attacker to display the absolute path to the directory that the agora.cgi script is stored in. This is possible by making a web request for a non-existent .html file.

The remote attacker may potentially use the disclosed information to aid in further "intelligent" attacks against the host running the vulnerable software.







 

Privacy Statement
Copyright 2008, SecurityFocus