Vulnerabilities
Vulnerable Software
Dcscripts:  >> Dcshop  Security Vulnerabilities
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
CVSS Score
5.0
EPSS Score
0.032
Published
2002-08-12
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.
CVSS Score
5.0
EPSS Score
0.042
Published
2001-12-06


Contact Us

Shodan ® - All rights reserved