Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alex Heiphetz Group EZShopper loadpage.cgi目录列表泄露漏洞
Vulnerability Description
EZShopper是一个基于Web的用Perl实现的电子商务软件包,由Alex Heiphetz Group公司开发和维护。 NSFOCUS安全小组发现AHG公司的EZshopper所带的loadpage.cgi脚本实现上存在输入验证漏洞,远程攻击者可以获得EZshopper目录的文件列表及其敏感文件内容。
CVSS Information
N/A
Vulnerability Type
N/A