Vulnerability Description
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zen-Cart | Zen Cart | <= 1.2.6d |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/18801PatchVendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=392886Patch
- http://www.vupen.com/english/advisories/2006/0546
- http://secunia.com/advisories/18801PatchVendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=392886Patch
- http://www.vupen.com/english/advisories/2006/0546
FAQ
What is CVE-2006-0697?
CVE-2006-0697 is a vulnerability with a CVSS score of 10.0 (HIGH). Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
How severe is CVE-2006-0697?
CVE-2006-0697 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0697?
Check the references section above for vendor advisories and patch information. Affected products include: Zen-Cart Zen Cart.