Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/25802 | vdb entry |
http://securityreason.com/securityalert/703 | third party advisory |
http://www.securityfocus.com/archive/1/430880/100/0/threaded | mailing list |
http://securityreason.com/securityalert/761 | third party advisory |
http://www.osvdb.org/24621 | exploit vdb entry patch |
http://secunia.com/advisories/19662 | exploit third party advisory vendor advisory |