5
CVSSv2

CVE-2000-0254

Published: 14/04/2000 Updated: 03/05/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The dansie shopping cart application cart.pl allows remote malicious users to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.

Vulnerable Product Search on Vulmon Subscribe to Product

craig dansie dansie shopping cart 3.0.4

Exploits

source: wwwsecurityfocuscom/bid/1115/info Appending specific variables and values to target/cgi-bin/cartpl? will allow remote users to perform certain actions "vars" will display the configuration settings of the application, which includes the username and password used for credit card transactions Environmental settings can be ...