5
CVSSv2

CVE-2000-1005

Published: 11/12/2000 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote malicious users to read arbitrary files via a .. (dot dot) attack on the page parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

extropia extropia webstore 1.0

extropia extropia webstore 2.0

Exploits

source: wwwsecurityfocuscom/bid/1774/info Extropia WebStore is an e-commerce shopping cart application consisting of routines for error handling, order processing, encrypted mailing, frames, Javascript and VBscript The routine web_storecgi does not properly handle the $file_extension variable if null characters are used For example i ...