Nessus Plugin #10532

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

eXtropia Web Store remote file retrieval

Family:
Remote file access
Category:
infos
Copyright:
This script is Copyright (C) 2000 Thomas Reinke
Summary:
eXtropia Web Store remote file retrieval
Version:
$Revision: 1.16 $
Cve_id:
CVE-2000-1005
Bugtraq_id:
1774
Xrefs:
-
Description:
eXtropia's Web Store shopping cart
program allows the remote file retrieval of any file
that ends in a .html extension. Further, by supplying
a URL with an imbedded null byte, the script can be made
to retrieve any file at all.

Example:
GET /cgi-bin/Web_Store/web_store.cgi?page=../../../../etc/passwd%00.html

will return /etc/passwd.

Solution: None available at this time

Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.