dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Dcshop |
Dcscripts |
1.002_beta (including) |
1.002_beta (including) |
References