Description
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by tombow & Randy Janinda · textremotecgi
https://www.exploit-db.com/exploits/19852
References (2)
Core 2
Core References
Exploit, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1115
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/4954
Scores
EPSS
0.0363
EPSS Percentile
88.0%
Details
Status
published
Products (1)
craig_dansie/dansie_shopping_cart
3.0.4
Published
Apr 14, 2000
Tracked Since
Feb 18, 2026