CVE-2002-1798 is a critical vulnerability affecting MidiCart PHP, PHP Plus, and PHP Maxi e-commerce platforms. It allows unauthenticated remote attackers to upload arbitrary PHP files, leading to remote code execution, or access sensitive credit card information directly. With a CVSS score of 9.1, this vulnerability is easily exploitable over the network with no user interaction, resulting in complete compromise of confidentiality and integrity. While not currently on CISA's KEV catalog or showing active exploitation, public exploit code exists on ExploitDB, and its high FAUCET Risk Score of 94/100 indicates significant potential danger. Despite its age and lack of recent community discussion or media coverage, the ease of exploitation and severe impact warrant attention for any remaining installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:midicart:midicart_php:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:midicart:midicart_php_maxi:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:midicart:midicart_php_plus:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.