Hassan Consulting Shopping Cart Directory Traversal Vulnerability
BID:1777
Info
Hassan Consulting Shopping Cart Directory Traversal Vulnerability
| Bugtraq ID: | 1777 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 07 2000 12:00AM |
| Updated: | Oct 07 2000 12:00AM |
| Credit: | Posted to Bugtraq on October 7, 2000 by f0bic <[email protected]>. |
| Vulnerable: |
Hassan Consulting Shopping Cart 1.18 |
| Not Vulnerable: | |
Discussion
Hassan Consulting Shopping Cart Directory Traversal Vulnerability
The $page variable in Hassan Consulting Shopping Cart does not properly check for insecure relative paths such as the double dot "..". Therefore, requesting the following URL will display the specified file:
http://target/cgi-bin/shop.cgi/page=../../../path/filename.ext
Successful exploitation could lead to a remote intruder gaining read access to any known file.
The $page variable in Hassan Consulting Shopping Cart does not properly check for insecure relative paths such as the double dot "..". Therefore, requesting the following URL will display the specified file:
http://target/cgi-bin/shop.cgi/page=../../../path/filename.ext
Successful exploitation could lead to a remote intruder gaining read access to any known file.
Exploit / POC
Hassan Consulting Shopping Cart Directory Traversal Vulnerability
http://target/cgi-bin/shop.cgi/page=../../../path/filename.ext
http://target/cgi-bin/shop.cgi/page=../../../path/filename.ext
Solution / Fix
Hassan Consulting Shopping Cart Directory Traversal Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Hassan Consulting Shopping Cart Directory Traversal Vulnerability
References:
References:
- Shopping Cart Product Homepage (Hassan Consulting)