CVE-2000-0396 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.9% (pctl 94)
Patch early
A public exploit exists.
Description
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 6.87% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-05-24 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| pacific software | carello |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Pacific Software Carello 1.2.1 - File Duplication / Source Disclosure | 2000-05-24 |
References
→ the Explorer · watch your stack · NVD