Quikstore File Disclosure Vulnerability

A vulnerability exists in several versions of Quikstore Shopping Cart, an ecommerce script from i-Soft.

A failure to properly validate user-supplied input can lead the script to disclose files not normally available to a remote user.

This could include any world-readable file on the affected host, including password files, server configuration information, credit card information and business models, and other sensitive data.


 

Privacy Statement
Copyright 2010, SecurityFocus