7.8
CVSSv2

CVE-2008-6279

Published: 25/02/2009 Updated: 26/02/2009
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote malicious users to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

rakhisoftware rakhisoftware shopping cart -

Exploits

source: wwwsecurityfocuscom/bid/32563/info RakhiSoftware Shopping Cart is prone to multiple remote vulnerabilities Exploiting these issues can allow attackers to obtain sensitive information, steal cookie data, access or modify data, or exploit latent vulnerabilities in the underlying database Set Cookie: PHPSESSID=' ...