CVE-2004-2024: High severity zen cart vulnerability
Published Dec 31, 2004
·Updated
The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via passwordforgotten.php.
Affected Software
1 affected component
Zen Cart Zen Cart=1.1.4
Remediation
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2024?
CVE-2004-2024 has a high severity level due to the potential for attackers to gain administrative privileges.
2
How do I fix CVE-2004-2024?
To fix CVE-2004-2024, upgrade to Zen Cart version 1.1.4 with patch 2 or later.
3
What are the potential impacts of CVE-2004-2024?
The potential impacts of CVE-2004-2024 include unauthorized access to the admin panel and manipulation of store settings.
4
Who is affected by CVE-2004-2024?
Users of Zen Cart version 1.1.4 prior to patch 2 are affected by CVE-2004-2024.
5
What is the nature of the vulnerability in CVE-2004-2024?
The nature of CVE-2004-2024 involves insecure debugging code that can be exploited through the password retrieval feature.