header-logo
Suggest Exploit
vendor:
1C: Arcadia Internet Store
by:
Unknown
N/A
CVSS
MEDIUM
Arbitrary File Disclosure
22
CWE
Product Name: 1C: Arcadia Internet Store
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:1c:arcadia_internet_store
Metasploit:
Other Scripts:
Platforms Tested: Windows NT/2000
Unknown

Arbitrary File Disclosure in 1C: Arcadia Internet Store

The 'tradecli.dll' component in 1C: Arcadia Internet Store allows remote attackers to disclose sensitive information by specifying an arbitrary file on the same drive as the webserver through a traversal attack.

Mitigation:

Apply a patch or update to the latest version of 1C: Arcadia Internet Store.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/2902/info

1C: Arcadia Internet Store is a online shopping utility for Microsoft Windows NT/2000 that is fully integratable with 1C: Enterprise, another popular Russian web-commerce utility.

One of the components of this package, 'tradecli.dll', allows users to specify a template file, the contents of which will be output. There is no filtering on '..\' character sequences. As a result, remote users can specify an arbitrary file on the same drive as the webserver by 'traversing' outside of the web root directory.

This vulnerability may disclose sensitive information to attackers. 

Exploit: http://host/script/tradecli.dll?template=..\..\..\..\..\path\to\file