vendor:
TomatoCart
by:
brain[pillow]
7.5
CVSS
HIGH
Local File Inclusion
CWE
Product Name: TomatoCart
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
TomatoCart 1.1 PostAuth Local File Include
The vulnerability allows an attacker to include local files by manipulating the 'pdf' parameter in the '/pdf.php' script. By specifying a relative path to a file, the attacker can read sensitive information, such as the '/etc/passwd' file.
Mitigation:
Apply the vendor-provided patch or upgrade to a newer version that addresses the vulnerability. Restrict access to the vulnerable script and sanitize user input to prevent directory traversal attacks.