Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2000-1092
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
0
Attacker Value
Unknown
CVE-2000-0187
Disclosure Date: February 27, 2000 (last updated February 22, 2025)
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
0
Attacker Value
Unknown
CVE-2000-0188
Disclosure Date: February 27, 2000 (last updated February 22, 2025)
EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
0