PT-2004-1447 · Shopcartcgi · Shopcartcgi
Publicado
2004-03-18
·
Atualizado
2017-07-11
·
CVE-2004-0293
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ShopCartCGI version 2.3
Description
A directory traversal issue allows remote attackers to retrieve arbitrary files by including a .. (dot dot) in a HTTP request. This can be done through requests to "gotopage.cgi" or "genindexpage.cgi" API endpoints, potentially exposing sensitive information.
Recommendations
For ShopCartCGI version 2.3, consider restricting access to the "gotopage.cgi" and "genindexpage.cgi" API endpoints until a patch is available. As a temporary workaround, disabling the ability to use .. (dot dot) in HTTP requests to these endpoints can help mitigate the risk.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Shopcartcgi