PT-2001-1990 · Dcshop · Dcshop

Publicado

2001-11-22

·

Atualizado

2017-12-19

·

CVE-2001-0821

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DCShop version 1.002 beta
Description The default configuration of the software places sensitive files in the cgi-bin directory. This could allow remote attackers to read sensitive data via an HTTP GET request for files such as orders.txt or auth user file.txt.
Recommendations For DCShop version 1.002 beta, consider relocating sensitive files outside the cgi-bin directory or restricting access to these files to prevent unauthorized reading. As a temporary workaround, restrict access to the cgi-bin directory to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0821

Produtos afetados

Dcshop