PT-2006-2881 · Webplus · Web+Shop
Revnic Vasile
·
Published
2006-04-20
·
Updated
2018-10-18
·
CVE-2006-1897
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Webplus (aka talentsoft) Web+Shop version 5.3.6
Description
The issue allows remote attackers to obtain sensitive information when the Redirect URL for "Script Not Found" Error is not configured. This is achieved by providing a quote (') or possibly other invalid value in the
storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.Recommendations
For Webplus (aka talentsoft) Web+Shop version 5.3.6, configure the Redirect URL for "Script Not Found" Error to prevent sensitive information disclosure. As a temporary workaround, consider restricting access to the
storeid parameter in the store.wml file to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Web+Shop