Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for Script Not Found Error is not configured, allows remote attackers to obtain sensitive information via a quote () or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a Script Not Found error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web+_shop | Talentsoft | 5.3.6 (including) | 5.3.6 (including) |