50325vdb entry
http://osvdb.org/50325 CVE-2008-6279
RakhiSoftware Shopping Cart - PHPSESSID Cookie Manipulation Full Path Disclosure
Record summary
CVE-2008-6279 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit.
Description
RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRakhiSoftware Shopping Cart - PHPSESSID Cookie Manipulation Full Path DisclosureExploitDB exploitby Charalambous GlafkosNot analyzed1 file
References
5packetstormsecurity.com
http://packetstormsecurity.com/0811-exploits/rakhi-sqlxssfpd.txt 32950Third-party advisory
http://secunia.com/advisories/32950 32563vdb entry
http://www.securityfocus.com/bid/32563 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6279