Happymall E-Commerce Software Normal_HTML.CGI File Disclosure Vulnerability
BID:7559
Info
Happymall E-Commerce Software Normal_HTML.CGI File Disclosure Vulnerability
| Bugtraq ID: | 7559 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2003 12:00AM |
| Updated: | May 12 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Julio Cesar <[email protected]>. |
| Vulnerable: |
HappyCGI HappyMall 4.4 HappyCGI HappyMall 4.3 |
| Not Vulnerable: | |
Discussion
Happymall E-Commerce Software Normal_HTML.CGI File Disclosure Vulnerability
IT has been reported that Happymall E-Commerce is prone to a file disclosure vulnerability. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to view the contents of sensitive system files. Files viewed in this manner would be accessed with the privileges of the Happymall process.
IT has been reported that Happymall E-Commerce is prone to a file disclosure vulnerability. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to view the contents of sensitive system files. Files viewed in this manner would be accessed with the privileges of the Happymall process.
Exploit / POC
Happymall E-Commerce Software Normal_HTML.CGI File Disclosure Vulnerability
No exploit is required.
The following proof of concept URL has been provided:
http://www.target.org/shop/normal_html.cgi?file=../../../../../../etc/issue%00
No exploit is required.
The following proof of concept URL has been provided:
http://www.target.org/shop/normal_html.cgi?file=../../../../../../etc/issue%00
Solution / Fix
Happymall E-Commerce Software Normal_HTML.CGI File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Happymall E-Commerce Software Normal_HTML.CGI File Disclosure Vulnerability
References:
References:
- One more flaw in Happymall (Julio Cesar
)