[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Comdev eCommerce wce.download.php Download Vulnerability
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Comdev eCommerce wce.download.php Download Vulnerability
- From: none@xxxxxxxx
- Date: 5 Aug 2005 01:55:55 -0000
Class: Input Validation Error
Vulnerable: Comdev Comdev eCommerce 3.0
The wce.download.php script (present in two locations) can be passed a
"download" http request parameter to download an arbitrary file on the
vulnerable server.
Example:
http://www.vulnerable.com/oneadmin/faqsupport/wce.download.php?download=../../config.php