CVE-2008-6321 describes an insufficient access control vulnerability in CF Shopkart 5.2.2, allowing remote attackers to directly access the cfshopkart52.mdb database file located under the web root. This flaw enables the retrieval of sensitive information, including usernames and passwords. With a CVSS score of 5.0, this vulnerability is easily exploitable over the network with low attack complexity and no authentication required, leading to a partial compromise of confidentiality. While not listed on the KEV catalog and with no Metasploit or Nuclei modules, an ExploitDB entry (EDB-7412) indicates the existence of public exploit code for SQL injection and file disclosure. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.2CPE matchmatch criteria | cpe:2.3:a:cfshopkart:cf_shopkart:5.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.