PT-2006-2881 · Webplus · Web+Shop

Revnic Vasile

·

Published

2006-04-20

·

Updated

2018-10-18

·

CVE-2006-1897

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Webplus (aka talentsoft) Web+Shop version 5.3.6
Description The issue allows remote attackers to obtain sensitive information when the Redirect URL for "Script Not Found" Error is not configured. This is achieved by providing a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.
Recommendations For Webplus (aka talentsoft) Web+Shop version 5.3.6, configure the Redirect URL for "Script Not Found" Error to prevent sensitive information disclosure. As a temporary workaround, consider restricting access to the storeid parameter in the store.wml file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1897

Affected Products

Web+Shop