CVE-2000-0187
high
📛 Threat Title
CVE-2000-0187
Description
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (3)
- cve@mitre.org NVD Recent CVEs
- cve@mitre.org NVD Recent CVEs
-
NVD detail: CVE-2000-0187
NVD Recent CVEs
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
Remediations (10)
-
web:cvevault.com
CVE Vault - Search and explore Common Vulnerabilities and Exposures ( CVE ) database. Find security vulnerabilities by CVE ID, vendor, severity, and year. Stay secure with comprehensive CVE information.
-
web:cwe.mitre.org
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.
-
web:owasp.org
The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:www.action1.com
This Patch Tuesday brings 55 vulnerability fixes from Microsoft, including six zero-days. Third-party overview includes actively exploited vulnerabilities in web browsers, Cisco, Fortinet, ServiceNow, Palo Alto, SAP, WordPress, Adobe, Oracle, and many more.
-
web:www.cisa.gov
Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.cvefind.com
CVE Find is a real-time vulnerability database indexing 351 731 security flaws ( CVE ) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1311 new CVEs were published in the last 7 days. Data aggregated from: MITRE Corporation ( CVE , CWE, CAPEC), National Vulnerability Database - NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
-
web:www.ninjaone.com
Catalog of Microsoft KB updates with insights on performance & user sentiment. Find out what's working, what's not, & make informed decisions.
-
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.