Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2000-0254

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2000-0254
Last Modified 10 Sep 2008 03:03:46
Published 14 Apr 2000 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2000-0254

Summary

The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.

Vulnerable Systems

Application

  • Craig Dansie Dansie Shopping Cart 3.0.4


References

XF - dansie-form-variables

BID - 1115


Last Updated: 27 May 2016 10:35:38