[ TITLE ....... ][ VirtueMart 2.0.2 Information Disclosure [ DATE ........ ][ 06.04.2012 [ AUTOHR ...... ][ http://hauntit.blogspot.com [ SOFT LINK ... ][ http://virtuemart.org [ VERSION ..... ][ 2.0.2 [ TESTED ON ... ][ LAMP [ ----------------------------------------------------------------------- [ [ 1. What is this? [ 2. What is the type of vulnerability? [ 3. Where is bug :) [ 4. More... [--------------------------------------------[ [ 1. What is this? This is very nice e-commerce webapp, You should try it! ;) [--------------------------------------------[ [ 2. What is the type of vulnerability? Information disclosure in this webapp. You should know that some of examples could not work in 'secured' php.ini. [--------------------------------------------[ [ 3. Where is bug :) http://joomla/index.php/en/dk?task=askquestion&virtuemart_product_id=limit%20100111111111111&virtuemart_category_id=1&tmpl=component Parameter shipto_virtuemart_country_id is also vulnerable. Parameter shipto_phone_1 is also vulnerable. [--------------------------------------------[ [ 4. More... - http://hauntit.blogspot.com - http://www.google.com - http://portswigger.net [ [--------------------------------------------[ [ All questions about new projects @ mail now :) ] [ Best regards [