5
CVSSv2

CVE-2000-0396

Published: 24/05/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The add.exe program in the Carello shopping cart software allows remote malicious users to duplicate files on the server, which could allow the malicious user to read source code for web scripts such as .ASP files.

Vulnerable Product Search on Vulmon Subscribe to Product

pacific software carello 1.2.1

Exploits

source: wwwsecurityfocuscom/bid/1245/info A remote user can gain read and write access on a target machine running Carello shopping cart software First, a user may create a duplicate of a known file in a known directory on the target host through addexe in /scripts/Carello Accessing target/scripts/Carello/addexe?C:\directory\f ...