Critical severity9.1NVD Advisory· Published Dec 31, 2002· Updated Apr 16, 2026
CVE-2002-1798
CVE-2002-1798
Description
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
Affected products
3- cpe:2.3:a:midicart:midicart_php:-:*:*:*:*:*:*:*
- cpe:2.3:a:midicart:midicart_php_maxi:-:*:*:*:*:*:*:*
- cpe:2.3:a:midicart:midicart_php_plus:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- archives.neohapsis.com/archives/bugtraq/2002-10/0016.htmlnvdBroken LinkExploit
- www.securityfocus.com/bid/5851nvdBroken LinkExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/5855nvdBroken LinkExploitThird Party AdvisoryVDB Entry
- www.iss.net/security_center/static/10306.phpnvdBroken Link
News mentions
0No linked articles in our index yet.