PT-2001-1990 · Dcshop · Dcshop
Published
2001-11-22
·
Updated
2017-12-19
·
CVE-2001-0821
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DCShop version 1.002 beta
Description
The default configuration of the software places sensitive files in the cgi-bin directory. This could allow remote attackers to read sensitive data via an HTTP GET request for files such as
orders.txt or auth user file.txt.Recommendations
For DCShop version 1.002 beta, consider relocating sensitive files outside the cgi-bin directory or restricting access to these files to prevent unauthorized reading. As a temporary workaround, restrict access to the cgi-bin directory to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dcshop