Summary
Comersus ASP shopping cart is a set of ASP scripts creating an online shoppingcart. It works on a database of your own choosing, default is msaccess, and includes online administration tools.
By accessing the /comersus_backoffice_install10.asp file it is possible to bypass the need to authenticate as an administrative user.
Solution
Delete the file '/comersus_backoffice_install10.asp' from the server as it is not needed after the installation process has been completed.
Severity
Classification
-
CVE CVE-2005-0301 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities