quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Quikstore | I-soft | * | * |