Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2000-1092

Disclosure Date: January 09, 2001 (last updated February 22, 2025)
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.
0
Attacker Value
Unknown

CVE-2000-0187

Disclosure Date: February 27, 2000 (last updated February 22, 2025)
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
0
Attacker Value
Unknown

CVE-2000-0188

Disclosure Date: February 27, 2000 (last updated February 22, 2025)
EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
0