OpenCart Cache Directory Traversal Vulnerability
BID:49507
Info
OpenCart Cache Directory Traversal Vulnerability
| Bugtraq ID: | 49507 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2011 12:00AM |
| Updated: | Sep 08 2011 12:00AM |
| Credit: | Dang Hai Son |
| Vulnerable: |
OpenCart OpenCart 1.4.9 OpenCart OpenCart 1.3.2 OpenCart OpenCart 1.1.9 OpenCart OpenCart 1.1.8 OpenCart OpenCart 1.5.1.1 OpenCart OpenCart 1.4.9.1 |
| Not Vulnerable: |
OpenCart OpenCart 1.5.1.2 |
Discussion
OpenCart Cache Directory Traversal Vulnerability
OpenCart is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the Web server. Information harvested may aid in launching further attacks.
OpenCart 1.5.1.1 and prior are vulnerable.
OpenCart is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the Web server. Information harvested may aid in launching further attacks.
OpenCart 1.5.1.1 and prior are vulnerable.
Exploit / POC
OpenCart Cache Directory Traversal Vulnerability
An attacker can use a Web browser to exploit this issue.
An attacker can use a Web browser to exploit this issue.
Solution / Fix
OpenCart Cache Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
OpenCart Cache Directory Traversal Vulnerability
References:
References:
- OpenCart Homepage (OpenCart)
- OpenCart Arbitrary File Creation (All versions) (OpenCart)