PT-2001-1990 · Dcshop · Dcshop

Published

2001-11-22

·

Updated

2017-12-19

·

CVE-2001-0821

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DCShop version 1.002 beta
Description The default configuration of the software places sensitive files in the cgi-bin directory. This could allow remote attackers to read sensitive data via an HTTP GET request for files such as orders.txt or auth user file.txt.
Recommendations For DCShop version 1.002 beta, consider relocating sensitive files outside the cgi-bin directory or restricting access to these files to prevent unauthorized reading. As a temporary workaround, restrict access to the cgi-bin directory to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0821

Affected Products

Dcshop