20000524 Alert: Carello File Creation flawmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-05/0285.html CVE-2000-0396
Pacific Software Carello 1.2.1 - File Duplication / Source Disclosure
Record summary
CVE-2000-0396 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPacific Software Carello 1.2.1 - File Duplication / Source DisclosureExploitDB exploitby Cerberus Security TeamNot analyzed1 file
References
31245vdb entry
http://www.securityfocus.com/bid/1245 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0396