7.5
CVSSv2

CVE-2005-1005

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ProfitCode PayProCart 3.0 allows remote malicious users to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

profitcode payprocart 3.0

Exploits

source: wwwsecurityfocuscom/bid/13006/info ProfitCode Software PayProCart may allow a remote attacker to carry out directory traversal attacks It is reported that this issue can be exploited by issuing a specially crafted HTTP GET request and supplying directory traversal sequences followed by a target file name through an affected para ...