Exploitation Summary
EIP tracks 1 public exploit for CVE-2000-0925. PoCs published by DCIST.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in Smartwin Technology CyberOffice Shopping Cart 2.0, where the _private directory is world-readable, allowing remote attackers to access sensitive data such as unencrypted credit card information.
Description
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in Smartwin Technology CyberOffice Shopping Cart 2.0, where the _private directory is world-readable, allowing remote attackers to access sensitive data such as unencrypted credit card information.