Nessus Plugin #10770

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

sglMerchant Information Disclosure Vulnerability

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2001 SecuriTeam
Summary:
sglMerchant Information Disclosure Vulnerability
Version:
$Revision: 1.16 $
Cve_id:
CAN-2001-1019
Bugtraq_id:
3309
Xrefs:
-
Description:

A CGI (view_item) that is a part of sglMerchant is installed.

This CGI suffers from a security vulnerability that makes it possible to escape
the bounding HTML root directory and read arbitrary system files.

Solution: Contact the author of the program
Risk factor : High

Additional information:
http://www.securiteam.com/unixfocus/5KP012K5FK.html
Generiert am 27.04.2005 um 18:49:54 Uhr.