| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.901302 |
| Category: | Web application abuses |
| Title: | TomatoCart 'json.php' Directory Traversal Vulnerability |
| Summary: | Check for directory traversal vulnerability in TomatoCart |
| Description: | Overview: This host is installed with TomatoCart and is prone to directory traversal vulnerability. Vulnerability Insight: The flaw is due to improper validation of user supplied input via the 'module' parameter to json.php, which allows attackers to read arbitrary files via a ../(dot dot) sequences. Impact: Successful exploitation could allow attackers to perform directory traversal attacks and read arbitrary files on the affected application and execute arbitrary script code. Impact Level: Application Affected Software/OS: TomatoCart version 1.2.0 Alpha 2 and prior Fix: No solution or patch is available as of 28th November, 2012. Information regarding this issue will be updated once the solution details are available. For updates refer to http://www.tomatocart.com/ References: http://osvdb.org/80689 http://xforce.iss.net/xforce/xfdb/74459 http://www.mavitunasecurity.com/local-file-inclusion-vulnerability-in-tomatocart/ http://packetstormsecurity.org/files/111291/TomatoCart-1.2.0-Alpha-2-Local-File-Inclusion.html |
| Cross-Ref: |
BugTraq ID: 52766 Common Vulnerability Exposure (CVE) ID: CVE-2012-5907 http://packetstormsecurity.org/files/111291/TomatoCart-1.2.0-Alpha-2-Local-File-Inclusion.html http://www.mavitunasecurity.com/local-file-inclusion-vulnerability-in-tomatocart/ http://www.securityfocus.com/bid/52766 http://osvdb.org/80689 XForce ISS Database: tomatocart-json-file-include(74459) http://xforce.iss.net/xforce/xfdb/74459 |
| Copyright | Copyright (C) 2012 SecPod |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|