VYPR

Dcshop

by Dcscripts

CVEs (2)

  • CVE-2001-0821Dec 6, 2001
    risk 0.04cvss epss 0.12

    The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.

  • CVE-2002-0492Aug 12, 2002
    risk 0.03cvss epss 0.06

    dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.