Arbitrary PHP File Upload and Sensitive Information Disclosure in MidiCart PHP, PHP Plus, and PHP Maxi

Arbitrary PHP File Upload and Sensitive Information Disclosure in MidiCart PHP, PHP Plus, and PHP Maxi

CVE-2002-1798 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.

Learn more about our Web Application Penetration Testing UK.