CVE-2006-3757 Information
Feb 14, 2021
cve
Description
index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain sensitive information via empty (1) _GET[] (2) _SESSION[] (3) _POST[] (4) _COOKIE[] or (5) _SESSION[] array parameters which reveals the installation path in an error message. NOTE: this issue might be resultant from a global overwrite vulnerability.
Reference
http://securityreason.com/securityalert/1253 http://www.securityfocus.com/archive/1/438805/100/200/threaded
Share on: