PT-2004-1447 · Shopcartcgi · Shopcartcgi

Publicado

2004-03-18

·

Atualizado

2017-07-11

·

CVE-2004-0293

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ShopCartCGI version 2.3
Description A directory traversal issue allows remote attackers to retrieve arbitrary files by including a .. (dot dot) in a HTTP request. This can be done through requests to "gotopage.cgi" or "genindexpage.cgi" API endpoints, potentially exposing sensitive information.
Recommendations For ShopCartCGI version 2.3, consider restricting access to the "gotopage.cgi" and "genindexpage.cgi" API endpoints until a patch is available. As a temporary workaround, disabling the ability to use .. (dot dot) in HTTP requests to these endpoints can help mitigate the risk.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0293

Produtos afetados

Shopcartcgi