5
CVSSv2

CVE-2000-1092

Published: 09/01/2001 Updated: 19/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote malicious users to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

alex heiphetz group ezshopper 3.0

alex heiphetz group ezshopper 2.0

Exploits

source: wwwsecurityfocuscom/bid/2109/info It is possible for a remote user to gain read access to various files that reside within the EZShopper directory By requesting a specially crafted URL utilizing loadpagecgi' application with a '/' appended, EZShopper will disclose the contents within the EZShopper directory As a result, it is p ...