Interchange 4.8.x/5.0 - Remote Information Disclosure

EDB-ID:

23895




Platform:

ASP

Date:

2004-03-30


source: https://www.securityfocus.com/bid/10005/info

It has been reported that Interchange may be prone to a remote information disclosure vulnerability allowing attackers to disclose contents of arbitrary variables via URI requests.

This issue may allow an attacker to gain access to sensitive information that may be used to launch further attacks against a system. 

http://www.example.com/cgi-bin/store/__SQLUSER__