geeeekShop 1.4 - Information Disclosure

EDB-ID:

23000

CVE:

N/A


Author:

G00db0y

Type:

webapps


Platform:

PHP

Date:

2003-08-09


source: https://www.securityfocus.com/bid/8380/info

geeeekShop is prone to multiple information disclosure vulnerabilities. Passing invalid data as URI parameters to geeeekShop scripts, will cause an error message to be displayed, which contains installation path information. Additionally it has been reported that a remote attacker may access site configuration scripts, which may lead to the disclosure of potentially sensitive information.

http://www.example.com/shop/?category=xxxxxx&parent=0&page=x&/'
http://www.example.com/shop/php_files/site.config.php