20030717 eStore SQL Injection Vulnerability & Path Disclosuremailing list
http://marc.info/?l=bugtraq&m=105845898003616&w=2 CVE-2003-0586
eStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path Disclosure
Record summary
CVE-2003-0586 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBeStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path DisclosureExploitDB exploitby BosenNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0586