5
CVSSv2

CVE-2002-0215

Published: 16/05/2002 Updated: 11/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Agora.cgi 3.2r up to and including 4.0 while in debug mode allows remote malicious users to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

steve kneizys agora.cgi 3.2d

steve kneizys agora.cgi 3.2e

steve kneizys agora.cgi 3.2f

steve kneizys agora.cgi 3.2g

steve kneizys agora.cgi 3.3b

steve kneizys agora.cgi 3.3c

steve kneizys agora.cgi 3.3d

steve kneizys agora.cgi 3.3e

steve kneizys agora.cgi 3.2k

steve kneizys agora.cgi 3.2l

steve kneizys agora.cgi 3.2m

steve kneizys agora.cgi 3.2n

steve kneizys agora.cgi 4.0b

steve kneizys agora.cgi 4.0c

steve kneizys agora.cgi 4.0d

steve kneizys agora.cgi 4.0e

steve kneizys agora.cgi 3.2a

steve kneizys agora.cgi 3.2c

steve kneizys agora.cgi 3.2h

steve kneizys agora.cgi 3.2j

steve kneizys agora.cgi 3.2q

steve kneizys agora.cgi 3.3a

steve kneizys agora.cgi 3.3f

steve kneizys agora.cgi 3.3j

steve kneizys agora.cgi 4.0a

steve kneizys agora.cgi 3.2

steve kneizys agora.cgi 3.2b

steve kneizys agora.cgi 3.2i

steve kneizys agora.cgi 3.2ja

steve kneizys agora.cgi 3.2p

steve kneizys agora.cgi 3.2r

steve kneizys agora.cgi 3.3i

steve kneizys agora.cgi 4.0

Exploits

source: wwwsecurityfocuscom/bid/3976/info Agoracgi is a freely available, open source shopping cart system When debug mode is enabled, it is possible for a remote attacker to display the absolute path to the directory that the agoracgi script is stored in This is possible by making a web request for a non-existent html file The r ...