PT-2006-5107 · Oscommerce · Oscommerce

Publicado

2006-08-23

·

Atualizado

2017-07-20

·

CVE-2006-4298

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions osCommerce versions prior to 2.2 Milestone 2 060817
Description The issue allows remote attackers to determine the existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1) tep cache also purchased, (2) tep cache manufacturers box, and (3) tep cache categories box functions.
Recommendations For osCommerce versions prior to 2.2 Milestone 2 060817, update to version 2.2 Milestone 2 060817 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4298

Produtos afetados

Oscommerce