Alex Heiphetz Group

Ezshopper

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.09%
  • Published 09.01.2001 05:00:00
  • Last modified 03.04.2025 01:03:51

loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.

Exploit
  • EPSS 13.39%
  • Published 27.02.2000 05:00:00
  • Last modified 03.04.2025 01:03:51

EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.

Exploit
  • EPSS 2.5%
  • Published 27.02.2000 05:00:00
  • Last modified 03.04.2025 01:03:51

EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.