TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Web+ |
Talentsoft |
4 (including) |
4 (including) |
References