Description
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.
Affected products
- bytes_interactive / web_shopper1.0 – 1.0
- bytes_interactive / web_shopper2.0 – 2.0