|
|
| |
| CommerceSQL is "for those of you out there that need a shopping cart that will handle more then a handful of products or one that will run incredibly fast", a vulnerability in the product allows remote file reading. |
| |
Credit:
The information has been provided by Mariusz Ciesla.
|
| |
By using a specially prepared GET request it is possible for an attacker to read remote files.
Example:
By requesting http://vulnerablesite/index.cgi?page=../../../../../../../../etc/passwd it is possible to retrieve the remote server's /etc/passwd file.
|
|
|