Valdersoft Shopping Cart *commonIncludePath* File Inclusion

Posted on Thursday, December 21, 2006 @ 11:59:01 UTC in Security
by Raven

SECUNIA ADVISORY ID: SA23464

VERIFY ADVISORY: http://secunia.com/advisories/23464/

CRITICAL: Highly critical

IMPACT: System access

SOFTWARE: Valdersoft Shopping Cart 3.x - http://secunia.com/product/4844/

DESCRIPTION: mdx has reported two vulnerabilities in Valdersoft Shopping Cart, which can be exploited by malicious people to compromise vulnerable systems.
Input passed to the "commonIncludePath" parameter in admin/include/common.php and include/common.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. The vulnerabilities are reported in version 3.0. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY: mdx

ORIGINAL ADVISORY: http://www.milw0rm.com/exploits/2964
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • ofigustavo
Server TrafficServer Traffic
  • Total: 482,345,891
  • Today: 30,093
Server InfoServer Info
  • Apr 19, 2024
  • 09:12 pm UTC