20020325 dcshop.cgi anybody can delete *.setup for databasemailing list
http://archives.neohapsis.com/archives/bugtraq/2002-03/0302.html CVE-2002-0492
DCShop Beta 1.0 - Form Manipulation
Record summary
CVE-2002-0492 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDCShop Beta 1.0 - Form ManipulationExploitDB exploitby pokleyzz sakamaniakaNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0492