Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2008-0736
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.077
EPSS Ranking
91.5%
CVSS Severity
CVSS v2 Score
5.0
References
http://securityreason.com/securityalert/3600
http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1
http://www.securityfocus.com/archive/1/487058/100/0/threaded
http://www.securityfocus.com/bid/27454
http://www.vupen.com/english/advisories/2008/0314
https://exchange.xforce.ibmcloud.com/vulnerabilities/39941
https://www.exploit-db.com/exploits/4988
http://securityreason.com/securityalert/3600
http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&PN=1
http://www.securityfocus.com/archive/1/487058/100/0/threaded
http://www.securityfocus.com/bid/27454
http://www.vupen.com/english/advisories/2008/0314
https://exchange.xforce.ibmcloud.com/vulnerabilities/39941
https://www.exploit-db.com/exploits/4988
Products affected by CVE-2008-0736
Shoppingtree
»
Candypress Store
»
Version:
4.1
cpe:2.3:a:shoppingtree:candypress_store:4.1
Shoppingtree
»
Candypress Store
»
Version:
4.1.1.26
cpe:2.3:a:shoppingtree:candypress_store:4.1.1.26
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved