PT-2006-4617 · Zen Cart · Zen Cart

O Y

·

Publicado

2006-07-21

·

Atualizado

2018-10-17

·

CVE-2006-3757

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zen Cart version 1.3.0.2
Description The issue allows remote attackers to obtain sensitive information via empty array parameters, which reveals the installation path in an error message. This is achieved by manipulating the GET[], SESSION[], POST[], or COOKIE[] arrays.
Recommendations For Zen Cart version 1.3.0.2, consider restricting access to the index.php file until a patch is available, or apply configuration changes to prevent the exposure of sensitive information through error messages.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3757

Produtos afetados

Zen Cart