eStore Settings.inc.PHP Path Disclosure Vulnerability
BID:8220
Info
eStore Settings.inc.PHP Path Disclosure Vulnerability
| Bugtraq ID: | 8220 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2003 12:00AM |
| Updated: | Jul 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Bosen <[email protected]>. |
| Vulnerable: |
Brooky eStore 1.0.2 b Brooky eStore 1.0.2 Brooky eStore 1.0.1 |
| Not Vulnerable: | |
Discussion
eStore Settings.inc.PHP Path Disclosure Vulnerability
eStore is prone to a path disclosure vulnerability.
It has been reported that a remote attacker may make a direct HTTP request for an eStore include script and in doing so trigger an error. The resulting error message will disclose potentially sensitive installation path information to the remote attacker.
eStore is prone to a path disclosure vulnerability.
It has been reported that a remote attacker may make a direct HTTP request for an eStore include script and in doing so trigger an error. The resulting error message will disclose potentially sensitive installation path information to the remote attacker.
Exploit / POC
eStore Settings.inc.PHP Path Disclosure Vulnerability
The following proof of concept has been supplied:
http://www.example.com/admin/settings.inc.php
The following proof of concept has been supplied:
http://www.example.com/admin/settings.inc.php
Solution / Fix
eStore Settings.inc.PHP Path Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
eStore Settings.inc.PHP Path Disclosure Vulnerability
References:
References:
- eStore Homepage (Brooky)
- eStore SQL Injection Vulnerability & Path Disclosure (Bosen
)