CVE-2002-1798 EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 4.6% (pctl 91)
Patch early
A public exploit exists.
Description
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 4.56% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-425 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| midicart | midicart php |
| midicart | midicart php maxi |
| midicart | midicart php plus |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Midicart PHP - Information Disclosure | 2002-10-02 |
| exploit-db | Midicart PHP - Arbitrary File Upload | 2002-10-02 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html
- http://www.iss.net/security_center/static/10306.php
- http://www.securityfocus.com/bid/5851
- http://www.securityfocus.com/bid/5855
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html
- http://www.iss.net/security_center/static/10306.php
- http://www.securityfocus.com/bid/5851
- http://www.securityfocus.com/bid/5855
→ the Explorer · watch your stack · NVD