|
Brought to you by:
Suppliers of:
|
|
|
| |
| Dansie Shopping Cart is "a premium, comprehensive, Perl shopping cart". A vulnerability in the product allows remote attackers to cause the product to reveal the path it was installed. |
| |
Credit:
The information has been provided by Dr`Ponidi.
|
| |
A remote user can send a request to cause the Dansie Shopping Cart to display an error message that indicates the installation path.
Exploit:
http://www.site.com/cgi-bin/cart.pl?db='
|
|
|
|
|