The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dansie_shopping_cart | Craig_dansie | 3.0.4 (including) | 3.0.4 (including) |