MEDIUM · 5.0

CVE-2002-1432

MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.

Vulnerability Description

MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Coxco SupportA-Cart2.0
Coxco SupportMetacart2.sql
Coxco SupportMidicart AspAll versions
Coxco SupportMidicart Asp MaxiAll versions
Coxco SupportMidicart Asp PlusAll versions
Coxco SupportSalescart-ProAll versions
Coxco SupportSalescart-StdAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-1432?

CVE-2002-1432 is a vulnerability with a CVSS score of 5.0 (MEDIUM). MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.

How severe is CVE-2002-1432?

CVE-2002-1432 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1432?

Check the references section above for vendor advisories and patch information. Affected products include: Coxco Support A-Cart, Coxco Support Metacart, Coxco Support Midicart Asp, Coxco Support Midicart Asp Maxi, Coxco Support Midicart Asp Plus.