Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than CVE-2007-5364. NOTE: this can be leveraged for reading certificate or key files if an installation places these files under the web document root.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ViArt Shop 'Ideal_Process.PHP' 目录遍历漏洞
Vulnerability Description
ViArt Shop 3.3 beta版本及其早期版本的iDEAL payment模块的ideal_process.php,可能允许远程攻击者可以借助"iDEAL交换",可能涉及非存在文件的错误信息,以获得证书信息和密匙文件的路径信息。
CVSS Information
N/A
Vulnerability Type
N/A