PT-1999-1225 · Quikstore · Quikstore
Published
1999-04-20
·
Updated
2016-10-18
·
CVE-1999-0607
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QuikStore shopping cart (affected versions not specified)
Description
The issue concerns insufficient access control in the quikstore.cgi component of the QuikStore shopping cart, which stores the quikstore.cfg file under the web document root. This allows remote attackers to obtain the cleartext administrator password, potentially leading to privilege escalation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quikstore