CVE-2003-1517 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 2% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| dansie | shopping cart |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dansie Shopping Cart - Server Error Message Installation Full Path Disclosure | 2003-10-20 |
References
- http://www.securiteam.com/securitynews/6T00T008KG.html
- http://www.securityfocus.com/bid/8860
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13461
- http://www.securiteam.com/securitynews/6T00T008KG.html
- http://www.securityfocus.com/bid/8860
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13461
→ the Explorer · watch your stack · NVD