CVE-2014-2009
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.
- Affected products
- Prestashop, Mpay24 Payment Module
- mpay24 Project mpay24
- ≤ 1.5.1, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.5.0
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 7.4% (94th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2014-09-12
CVE-2014-2009 at NVD
4 known exploits for CVE-2014-2009
Proof-of-concept code and exploit modules indexed by Sploitus