Description
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Dr_Ponidi · textwebappscgi
https://www.exploit-db.com/exploits/23266
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://www.securiteam.com/securitynews/6T00T008KG.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13461
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/8860
Scores
EPSS
0.0459
EPSS Percentile
89.3%
Details
CWE
CWE-200
Status
published
Products (1)
dansie/shopping_cart
Published
Dec 31, 2003
Tracked Since
Feb 18, 2026