CVE-2009-4323
The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) install.txt, which allows remote attackers to obtain sensitive information, delete the database, and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) install.txt, which allows remote attackers to obtain sensitive information, delete the database, and conduct other attacks via a direct request, different vulnerabilities than CVE-2009-4321 and CVE-2009-4322.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- zen-cart/zen cart
- Source
- cve@mitre.org
References
- http://www.zen-cart.com/forum/showthread.php?t=142784Vendor Advisory
- http://www.zen-cart.com/forum/showthread.php?t=142784Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.