[原文]Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.
Web+Shop contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker submits a request to the store.wml script with an invalid value in the 'storeid' variable, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
Upgrade to version 6.0 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: Configure a URL which Web+Shop should be directed to if an error 10220 (Script File Error) is encountered.