6.4
CVSSv2

CVE-2002-0943

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

MetaCart2.sql stores the user database under the web document root without access controls, which allows remote malicious users to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.

Vulnerable Product Search on Vulmon Subscribe to Product

metalinks metacart2.sql