[] NeoSense

Interchange 4.8.x/5.0 - Remote Information Disclosure

Author: anonymous
type: webapps
platform: asp
port: 
date_added: 2004-03-30 
date_updated: 2013-01-05 
verified: 1 
codes: CVE-2004-0374;OSVDB-4670 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/10005/info

It has been reported that Interchange may be prone to a remote information disclosure vulnerability allowing attackers to disclose contents of arbitrary variables via URI requests.

This issue may allow an attacker to gain access to sensitive information that may be used to launch further attacks against a system.

http://www.example.com/cgi-bin/store/__SQLUSER__