Posted on Tuesday, December 05, 2006 @ 10:48:48 CST in Security
by Raven
SECUNIA ADVISORY ID: SA23168
VERIFY ADVISORY: http://secunia.com/advisories/23168/
CRITICAL: Moderately critical
IMPACT: Exposure of sensitive information
SOFTWARE: Quick.Cart 2.x - http://secunia.com/product/12801/
DESCRIPTION: r0ut3r has reported some vulnerabilities in Quick.Cart, which can be exploited by malicious people to disclose sensitive information. Successful exploitation requires that "register_globals" is enabled and "magic_quotes_gpc" is disabled. The vulnerabilities are reported in version 2.0. Other versions may also be affected. Input passed to the "config[db_type]" parameter in multiple files is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal attacks.
Examples: Read More...