PT-2002-1543 · Dcshop · Dcshop
Published
2002-06-11
·
Updated
2008-09-05
·
CVE-2002-0492
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
DCShop version 1.002 Beta
Description
The issue allows remote attackers to delete arbitrary setup files by utilizing a null character in the
database parameter.Recommendations
For DCShop version 1.002 Beta, consider restricting access to the dcshop.cgi script until a patch is available, and avoid using null characters in the
database parameter to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dcshop