CVE-2002-1798

CRITICAL

MidiCart PHP - RCE

Title source: llm

Description

MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/21894
exploitdb WRITEUP VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/21896

Scores

CVSS v3 9.1
EPSS 0.0516
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-425
Status draft

Affected Products (3)

midicart/midicart_php
midicart/midicart_php_maxi
midicart/midicart_php_plus

Timeline

Published Dec 31, 2002
Tracked Since Feb 18, 2026