CVE-2005-2543

Comdev eCommerce 3.0 - Directory Traversal via wce.download.php Download Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2543. PoCs published by anonymous.

AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in Comdev eCommerce. It provides a URL example to exploit the vulnerability and disclose arbitrary local files.

Description

Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by anonymous · textwebappsphp
https://www.exploit-db.com/exploits/26080

This is a writeup describing a directory traversal vulnerability in Comdev eCommerce. It provides a URL example to exploit the vulnerability and disclose arbitrary local files.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Comdev eCommerce
No auth needed
Prerequisites: Access to the vulnerable web application
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14479
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112327874920062&w=2

Scores

EPSS 0.0599
EPSS Percentile 92.6%

Details

Status published
Products (1)
comdev/comdev_ecommerce 3.0
Published Aug 10, 2005
Tracked Since Feb 18, 2026