Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_shopper | Bytes_interactive | 1.0 (including) | 1.0 (including) |
Web_shopper | Bytes_interactive | 2.0 (including) | 2.0 (including) |