CVE-2003-0586

Brooky eStore <1.0.2b - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0586. PoCs published by Bosen.

AI-analyzed exploit summary This is a writeup describing a path disclosure vulnerability in eStore. The vulnerability allows an attacker to disclose sensitive installation path information by making a direct HTTP request to an include script, triggering an error message.

Description

Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Bosen · textwebappsphp
https://www.exploit-db.com/exploits/22925

This is a writeup describing a path disclosure vulnerability in eStore. The vulnerability allows an attacker to disclose sensitive installation path information by making a direct HTTP request to an include script, triggering an error message.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: eStore (version not specified)
No auth needed
Prerequisites: Access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105845898003616&w=2

Scores

EPSS 0.0550
EPSS Percentile 91.8%

Details

Status published
Products (1)
brooky/estore 1.0.2b
Published Aug 18, 2003
Tracked Since Feb 18, 2026