PT-2012-6240 · Opensolution · Open Solution Quick.Cart
Haunt It
·
Publicado
2012-11-27
·
Atualizado
2017-08-29
·
CVE-2012-6049
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open Solution Quick.Cart version 5.0
Description
The issue allows remote attackers to obtain sensitive information. This can be achieved by providing a long string or invalid characters in a
cookie, which results in an error message that reveals the installation path.Recommendations
For Open Solution Quick.Cart version 5.0, consider validating and sanitizing cookie inputs to prevent the disclosure of sensitive information. As a temporary workaround, restrict access to error messages that may contain installation path details until a proper fix is applied.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Open Solution Quick.Cart