Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc38-cj6h-xrxf

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.

Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.

EPSS

Процентиль: 71%
0.00674
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.

EPSS

Процентиль: 71%
0.00674
Низкий