CVE-2000-0396
UnknownEPSS 6.87%
Last modified
CVE-2000-0396 is a vulnerability of currently unknown severity. The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.. EPSS estimates a 6.87% chance of exploitation in the next 30 days.
Description
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pacific Software | Carello | 1.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2000-0396?
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
How severe is CVE-2000-0396?
Severity scoring for CVE-2000-0396 is pending analysis. The EPSS model estimates a 6.87% probability of exploitation in the next 30 days.
How do I fix CVE-2000-0396?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2000
- CVE-2000-0390Buffer overflow in krb425_conv_principal function in Kerbero…
- CVE-2000-0391Buffer overflow in krshd in Kerberos 5 allows remote attacke…
- CVE-2000-0392Buffer overflow in ksu in Kerberos 5 allows local users to g…
- CVE-2000-0393The KDE kscd program does not drop privileges when executing…
- CVE-2000-0394NetProwler 3.0 allows remote attackers to cause a denial of …
- CVE-2000-0395Buffer overflow in CProxy 3.3 allows remote users to cause a…
- CVE-2000-0397The EMURL web-based email account software encodes predictab…
- CVE-2000-0398Buffer overflow in wconsole.dll in Rockliffe MailSite Manage…
- CVE-2000-0399Buffer overflow in MDaemon POP server allows remote attacker…
- CVE-2000-0400The Microsoft Active Movie ActiveX Control in Internet Explo…
- CVE-2000-0401Buffer overflows in redirect.exe and changepw.exe in PDGSoft…
- CVE-2000-0402The Mixed Mode authentication capability in Microsoft SQL Se…
Are you affected by CVE-2000-0396?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
