Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dansie Shopping Cart Server错误消息安装路径泄露漏洞
Vulnerability Description
Dansie Shopping Cart是一款在线购物系统。 Dansie Shopping Cart没有正确处理用户提交请求,远程攻击者可以利用这个漏洞获得应用程序安装路径。 由于程序包含的cart.pl脚本对用户提交的db参数缺少正确处理,提交非法数据可返回包含安装路径信息的错误消息给攻击者。攻击者可以利用这些信息进一步对系统进行攻击。
CVSS Information
N/A
Vulnerability Type
N/A