PT-2001-1990 · Dcshop · Dcshop
Publicado
2001-11-22
·
Atualizado
2017-12-19
·
CVE-2001-0821
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DCShop version 1.002 beta
Description
The default configuration of the software places sensitive files in the cgi-bin directory. This could allow remote attackers to read sensitive data via an HTTP GET request for files such as
orders.txt or auth user file.txt.Recommendations
For DCShop version 1.002 beta, consider relocating sensitive files outside the cgi-bin directory or restricting access to these files to prevent unauthorized reading. As a temporary workaround, restrict access to the cgi-bin directory to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dcshop