E-market is commercial software made by korean company, includes shopping mall, community , e-crm (e-customer relationship management) , group buying ,weblog, auction, estimate sheet , and other features
Remote command execution on 'becommunity' (modules that support by BBS e-market professional) makes insecure calls to the include() function of PHP (works on " pageurl= " functions ) which can allow the inclusion of remote files, and thereby the execution of arbitrary commands by remote user with the web server user permissions, usually 'nobody' .
A remote user can access the file to cause the system to display an error message that indicates the installation path. The resulting error message will disclose potentially sensitive installation path information to the remote attacker.