5
CVSSv2

CVE-2002-0492

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

dcshop.cgi in DCShop 1.002 Beta allows remote malicious users to delete arbitrary setup files via a null character in the database parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dcscripts dcshop 1.002_beta

Exploits

source: wwwsecurityfocuscom/bid/4356/info DCShop Beta is a freely available shopping cart system, written in Perl It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems It is possible to overwrite setup files (*setup) by submitting attacker-supplied form data followed by a null character (%00) The ...