VulnerabilityModified
CVE-2000-1092
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
MEDIUM 5.0EPSS 7.49%
Does this matter?
Lower severity and a low EPSS score (7.49%). Track it; it rarely justifies an emergency change on its own.
Description
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.49% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- alex heiphetz group/ezshopper
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=97676270729984&w=2
- http://www.securityfocus.com/bid/2109Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5740
- http://marc.info/?l=bugtraq&m=97676270729984&w=2
- http://www.securityfocus.com/bid/2109Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5740
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.