CVE-2001-0821
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.
Scoring
- CVSS base score
- 0.59
- EPSS probability
- 11.73%
- Published
- 2001-11-22
- Last modified
- 2026-03-16
Affected products
- n/a n/a