Zen Cart "url" Processing Remote File Disclosure Vulnerability
Description
A vulnerability has been identified in Zen Cart, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "extras/curltest.php" script that does not validate the "url" parameter, which could be exploited to disclose the contents of arbitrary files.
Vulnerable Products
Vulnerable Software: Zen Cart versio 1.3.8a and prior