![]() |
CART32 expdate |
|
|
|
| FAQ | |||
|
|
Summary
A privileged access to the cart32 server application has been seen.
Details
Cart32 is an online shopping cart system developed by McMurtrey/Whitaker & Associates. A vulnerability in the cart32.exe CGI executable could allow a remote attacker to retrieve sensitive information about the server installation, including environment settings and a list of programs in the CGI-BIN directory. A remote attacker can exploit this vulnerability by appending the string "/expdate" to a request for the cart32.exe CGI.
| more information |
|
| ||||||||||
Version appeared: 3.5