COMMAND

    Mercantyle

SYSTEMS AFFECTED

    WinNT

PROBLEM

    Mark  O'Neill  found  following.   It  concerns  a  product called
    Mercantyle from Triptych (www.triptych.co.uk).  It is an  NT-based
    product used on bookstore sites around the world.  However, it  is
    very vulnerable to simple URL attacks such as:

        http://www.watkinsbooks.com/live/twist/twist.plx?form=3D\winnt\system32\hardware.inf

    In  the  case  of  the  above  site,  any  file on their server is
    available  simply  by  passing  its  name to the twist.plx script.
    There are other security holes  also.  It is astonishing  how many
    security holes are in this software.

SOLUTION

    Nothing yet.