5
CVSSv2

CVE-2008-0736

Published: 13/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote malicious users to obtain the path via a certain value of the FedExAccount parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

shoppingtree candypress store 4.1

shoppingtree candypress store 4.1.1.26

Exploits

########################## WwWBugReportir ########################################### # # AmnPardaz Security Research & Penetration Testing Group # # Title: [CandyPress] eCommerce suite # Vendor: wwwcandypresscom/ # Bugs: SQL Injection + XSS + Path Disclosure in CandyPress # Vulnerable Version: 41126 # Exploit: Available # Fi ...