CVE-2000-0430

Cart32 - Information Disclosure via /expdate URL

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0430. PoCs published by cassius.

AI-analyzed exploit summary This exploit describes an information leakage vulnerability in Cart32.exe where appending '/expdate' to the URL exposes server variables, administrative directory paths, and potentially CGI-bin contents. The attack is trivial and requires no authentication.

Description

Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by cassius · textremotewindows
https://www.exploit-db.com/exploits/20019

This exploit describes an information leakage vulnerability in Cart32.exe where appending '/expdate' to the URL exposes server variables, administrative directory paths, and potentially CGI-bin contents. The attack is trivial and requires no authentication.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Cart32.exe (version unspecified)
No auth needed
Prerequisites: Network access to the target server
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=95738697301956&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1358

Scores

EPSS 0.0592
EPSS Percentile 92.5%

Details

Status published
Products (1)
mcmurtrey_whitaker_and_associates/cart32 3.0
Published May 03, 2000
Tracked Since Feb 18, 2026