C-Cart Path Disclosure Vulnerability
BID:8368
Info
C-Cart Path Disclosure Vulnerability
| Bugtraq ID: | 8368 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2003 12:00AM |
| Updated: | Aug 08 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to G00db0y <[email protected]>. |
| Vulnerable: |
Polyspaston Software C-Cart 1.0 |
| Not Vulnerable: | |
Discussion
C-Cart Path Disclosure Vulnerability
C-Cart is prone to a path disclosure vulnerability. Passing invalid data as a URI parameter to several C-Cart scripts will cause an error message to be displayed, which contains installation path information.
C-Cart is prone to a path disclosure vulnerability. Passing invalid data as a URI parameter to several C-Cart scripts will cause an error message to be displayed, which contains installation path information.
Exploit / POC
C-Cart Path Disclosure Vulnerability
The following proof of concept has been supplied:
http://www.example.com/shop/search.php?q='
http://www.example.com/shop/show.php?q='
The following proof of concept has been supplied:
http://www.example.com/shop/search.php?q='
http://www.example.com/shop/show.php?q='
Solution / Fix
C-Cart Path Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
C-Cart Path Disclosure Vulnerability
References:
References:
- C-Cart Homepage (Polyspaston Software)
- ZH2003-16SA (security advisory): C-Cart Shopping Cart Path Disclosure (G00db0y
)