CVE-2006-0697: Critical severity Zen-cart Zen Cart vulnerability
Published Feb 15, 2006
·Updated
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
Affected Software
11 affected components
Zen-cart Zen Cart=1.2.4.1
Zen-cart Zen Cart=1.2.1d
Zen-cart Zen Cart=1.2.3d
Zen-cart Zen Cart<=1.2.6d
Zen-cart Zen Cart=1.1.3
Zen-cart Zen Cart=1.1.0
Zen-cart Zen Cart=1.2.1-patch1
Zen-cart Zen Cart=1.2.0d
Zen-cart Zen Cart=1.2.4d
Zen-cart Zen Cart=1.2.5d
Zen-cart Zen Cart=1.2.2d
Remediation
Patch Available
Event History
Feb 15, 2006
CVE Published
11:06 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0697?
CVE-2006-0697 has a medium severity rating due to the unauthorized access it allows to the admin includes directory.
2
How do I fix CVE-2006-0697?
To fix CVE-2006-0697, ensure that proper directory permissions are set for the admin/includes directory.
3
Which versions of Zen Cart are affected by CVE-2006-0697?
CVE-2006-0697 affects Zen Cart versions prior to 1.2.7, including 1.1.0 through 1.2.6d.
4
What impact could CVE-2006-0697 have on my Zen Cart installation?
CVE-2006-0697 could potentially allow remote attackers to exploit unspecified vulnerabilities due to lack of directory protection.
5
Is there an official patch for CVE-2006-0697?
No official patch is available for CVE-2006-0697, so users should implement manual security measures to protect their installations.