PT-2007-6499 · Viart · Viart Shop

Published

2007-10-15

·

Updated

2018-10-15

·

CVE-2007-5463

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ViArt Shop versions 3.3 beta and earlier
Description: The issue in the iDEAL payment module allows remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction". This could involve error messages for nonexistent files when using fopen. If the certificate or key files are placed under the web document root, this issue can be leveraged to read these sensitive files.
Recommendations: For versions 3.3 beta and earlier, consider restricting access to the ideal process.php file in the iDEAL payment module to minimize the risk of exploitation. Additionally, ensure that certificate and key files are not placed under the web document root to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5463

Affected Products

Viart Shop