Description
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).
Affected products
- cgicentral / webstore_4004.14 – 4.14
- cgicentral / webstore_400cs4.14 – 4.14