CVE-2005-3997: Low severity Zen Cart Zen Cart vulnerability
Zen Cart 1.2.6d and earlier, under certain PHP configurations, allows remote attackers to obtain sensitive information via direct requests to files in the admin/includes directory, including (1) graphs/bannerdaily.php, (2) graphs/bannerinfobox.php, (3) graphs/banneryearly.php, (4) graphs/bannermonthly.php, (5) applicationbottom.php, (6) attributespreview.php, (7) modules/categoryproductlisting.php, (8) modules/copytoconfirm.php, (9) modules/deleteproductconfirm.php, and (10) modules/moveproductconfirm.php, which leaks the web server path in the resulting error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3997?
CVE-2005-3997 has been classified as a medium-severity vulnerability, allowing information disclosure.
How do I fix CVE-2005-3997?
To fix CVE-2005-3997, upgrade Zen Cart to version 1.3.0 or later to ensure that sensitive files are not accessible.
What files are affected by CVE-2005-3997?
CVE-2005-3997 affects files in the admin/includes directory, such as graphs/banner_daily.php and others.
Who is impacted by CVE-2005-3997?
Users of Zen Cart versions 1.2.6d and earlier are primarily impacted by CVE-2005-3997.
Can CVE-2005-3997 lead to data breaches?
Yes, CVE-2005-3997 can potentially lead to unauthorized access to sensitive information, which may result in data breaches.