Description
|
|
Multiple vulnerabilities have been identified in Multi-lingual E-Commerce System, which could be exploited by remote attackers to gain knowledge of sensitive information or manipulate certain data.
The first issue is caused by an input validation error in the "index.php" script when processing the "page" parameter, which could be exploited by remote attackers to include or disclose the contents of local files with the privileges of the web server.
The second vulnerability is caused due to the "admin/inc/database.inc" file being publicly accessible, which could allow attackers to disclose database credentials.
The third issue is caused by due to missing authentication in the administrative interface, which could allow remote attackers to gain unauthorized administrative access to a vulnerable application and perform administrative tasks.
|