CVE-2002-0492
Published Aug 12, 2002dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
Vendor/product archive
2 CVEs tagged to dcscripts / dcshop — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request f…