Google Search: (inurl:/shop.cgi/page=) | (inurl:/shop.pl/page=)
brasileiro rates this entry 8 out of 10.
Submitted: 2004-11-07 07:14:39
Added by: brasileiro
This is a “double dork” finds two different shopping carts, both vulnerable1) Cyber-Village Online Consulting Shopping CartCyber-Village’s script is known to not sanitize the user input properly which leads to code execution problems.2) Hassan Consulting’s Shopping CartFor Hassan’s cart it is reported that a remote user can request the ‘shop.cfg’ and that the script allows directory traversal.