PT-2002-2740 · Oscommerce · Oscommerce
Publicado
2002-12-31
·
Atualizado
2011-06-29
·
CVE-2002-2019
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
osCommerce (a.k.a. Exchange Project) version 2.1
Description
The issue allows remote attackers to execute arbitrary PHP code via the
include file parameter in the include once.php file.Recommendations
For osCommerce (a.k.a. Exchange Project) version 2.1, consider restricting access to the include once.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the
include file parameter in the affected file until the issue is resolved.Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oscommerce