Exploitation Summary
EIP tracks 1 public exploit for CVE-2000-1092. PoCs published by Nsfocus.
AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in EZShopper's loadpage.cgi, allowing remote attackers to read arbitrary files by manipulating the URL. It includes examples for both v2.0 and v3.0, demonstrating path traversal sequences to access sensitive files like /etc/passwd.
Description
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
Exploits (1)
The exploit describes a directory traversal vulnerability in EZShopper's loadpage.cgi, allowing remote attackers to read arbitrary files by manipulating the URL. It includes examples for both v2.0 and v3.0, demonstrating path traversal sequences to access sensitive files like /etc/passwd.