5
CVSSv2

CVE-2005-2543

Published: 10/08/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote malicious users to download arbitrary files via a .. (dot dot) in the download parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

comdev comdev ecommerce 3.0

Exploits

source: wwwsecurityfocuscom/bid/14479/info Comdev eCommerce is prone to a directory traversal vulnerability A remote unauthorized user can disclose the contents of arbitrary local files through the use of directory traversal strings '/' relative to the Web application's root path Exploitation of this vulnerability could lead to a los ...