Lucene search

K
cve[email protected]CVE-2005-3997
HistoryDec 05, 2005 - 12:03 a.m.

CVE-2005-3997

2005-12-0500:03:00
web.nvd.nist.gov
30
zen cart
cve-2005-3997
security vulnerability
sensitive information disclosure
php configurations
remote attack

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.9%

Zen Cart 1.2.6d and earlier, under certain PHP configurations, allows remote attackers to obtain sensitive information via direct requests to files in the admin/includes directory, including (1) graphs/banner_daily.php, (2) graphs/banner_infobox.php, (3) graphs/banner_yearly.php, (4) graphs/banner_monthly.php, (5) application_bottom.php, (6) attributes_preview.php, (7) modules/category_product_listing.php, (8) modules/copy_to_confirm.php, (9) modules/delete_product_confirm.php, and (10) modules/move_product_confirm.php, which leaks the web server path in the resulting error message.

Affected configurations

NVD
Node
zen_cartzen_cartRange1.2.6d
CPENameOperatorVersion
zen_cart:zen_cartzen cartle1.2.6d

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.9%

Related for CVE-2005-3997