J-Security Center

Title: Quikstore File Disclosure Vulnerability

Severity: HIGH

Description:

A vulnerability exists in several versions of Quikstore Shopping Cart, an ecommerce script from i-Soft.

A failure to properly validate user-supplied input can lead the script to disclose files not normally available to a remote user.

This could include any world-readable file on the affected host, including password files, server configuration information, credit card information and business models, and other sensitive data.

Affected Products:

  • Quikstore Quikstore 2.0.0
  • Quikstore Quikstore 2.9.10
  • Quikstore Quikstore 2.9.5

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.