SourceCodester Online Eyewear Shop
cpe:2.3:a:online_eyewear_shop_project:online_eyewear_shop:*:*:*:*:*:*:*
- 1.0
A directory traversal vulnerability has been identified in SourceCodester Online Eyewear Shop version 1.0. The issue resides in an unknown function of the file '/oews/admin/', where multiple sub-directories are affected. This vulnerability allows remote attackers to traverse directories and access arbitrary files, potentially leading to the exposure of sensitive server information.
Exploitation of this vulnerability allows for unauthorized directory traversal, enabling access to restricted files and sensitive server information.
The vulnerability can be reproduced by sending a GET request to '/oews/admin/inc/', '/oews/admin/inquiries', or '/oews/admin/system_info'. This can be done using a web browser or a tool like cURL, without any special privileges or authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.