Home Services Publications News About us Contact Recruitment Site map

May, 2008

April, 2008

March, 2008

February, 2008

January, 2008

December, 2007


News archives

News
March 07, 2008
MWR InfoSecurity publish Elastic Path Advisory


An advisory has been released today by MWR InfoSecurity relating to Elastic Path ecommerce software versions 4.1 and 4.1.1. Multiple input validation vulnerabilities were identified within the Elastic Path application. As a result, directory traversal was possible allowing unrestricted file system access to the remote server. The impact of the vulnerabilities could enable an attacker to upload and download files from arbitrary locations on the affected system.

The vendor has released a patch to address these vulnerabilities. To obtain the patch users must contact the vendor at support@elasticpath.com or
http://www.elasticpath.com/support/.

The full advisory can be viewed here.
On Top
Penetration testing
Application Security Testing
Wireless Testing
Fasthold Vulnerability Assessment
Load Testing
Security Management Consultancy
Firewall Testing
Internal Penetration Testing
Physical Testing

 

home       services       news       about us       contact       recruitment       sitemap

MWR InfoSecurity St Clement House Alencon Link Basingstoke Hants RG21 7SB
Tel: 01256 300920   Fax: 01256 844083