Vulnerabilities > CVE-2000-0925 - Unspecified vulnerability in Smartwin Technology Cyberoffice Shopping Cart 2.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
smartwin-technology
exploit available

Summary

The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.

Vulnerable Configurations

Part Description Count
Application
Smartwin_Technology
1

Exploit-Db

descriptionSmartWin CyberOffice Shopping Cart 2.0 Client Information Disclosure Vulnerability. CVE-2000-0925. Remote exploit for windows platform
idEDB-ID:20248
last seen2016-02-02
modified2000-10-02
published2000-10-02
reporterDCIST
sourcehttps://www.exploit-db.com/download/20248/
titleSmartWin CyberOffice Shopping Cart 2.0 Client Information Disclosure Vulnerability