C-Cart 1.0 - Full Path Disclosure
Author: G00db0y
type: webapps
platform: php
port:
date_added: 2003-08-08
date_updated: 2012-11-29
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/8368/info
C-Cart is prone to a path disclosure vulnerability. Passing invalid data as a URI parameter to several C-Cart scripts will cause an error message to be displayed, which contains installation path information.
http://www.example.com/shop/search.php?q='
http://www.example.com/shop/show.php?q='