vendor:
1C: Arcadia Internet Store
by:
Unknown
N/A
CVSS
MEDIUM
Arbitrary File Disclosure
22
CWE
Product Name: 1C: Arcadia Internet Store
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:1c:arcadia_internet_store
Platforms Tested: Windows NT/2000
Unknown
Arbitrary File Disclosure in 1C: Arcadia Internet Store
The 'tradecli.dll' component in 1C: Arcadia Internet Store allows remote attackers to disclose sensitive information by specifying an arbitrary file on the same drive as the webserver through a traversal attack.
Mitigation:
Apply a patch or update to the latest version of 1C: Arcadia Internet Store.