PT-2012-6240 · Opensolution · Open Solution Quick.Cart
Haunt It
·
Published
2012-11-27
·
Updated
2017-08-29
·
CVE-2012-6049
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open Solution Quick.Cart version 5.0
Description
The issue allows remote attackers to obtain sensitive information. This can be achieved by providing a long string or invalid characters in a
cookie, which results in an error message that reveals the installation path.Recommendations
For Open Solution Quick.Cart version 5.0, consider validating and sanitizing cookie inputs to prevent the disclosure of sensitive information. As a temporary workaround, restrict access to error messages that may contain installation path details until a proper fix is applied.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Solution Quick.Cart