7.5
CVSSv2

CVE-2003-0586

Published: 18/08/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Brooky eStore 1.0.1 up to and including 1.0.2b allows remote malicious users to obtain sensitive path information via a direct HTTP request to settings.inc.php.

Vulnerable Product Search on Vulmon Subscribe to Product

brooky estore 1.0.2b

Exploits

source: wwwsecurityfocuscom/bid/8220/info eStore is prone to a path disclosure vulnerability It has been reported that a remote attacker may make a direct HTTP request for an eStore include script and in doing so trigger an error The resulting error message will disclose potentially sensitive installation path information to the remote ...