PT-2018-14748 · Oscommerce · Oscommerce

Hexifeo

·

Publicado

2018-11-06

·

Atualizado

2020-08-24

·

CVE-2018-18965

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions osCommerce version 2.3.4.1
Description The issue is related to an incomplete '.htaccess' file for blacklist filtering in the product page, allowing alternative cases for HTML execution. This includes files with no extension or unrecognized extensions, such as 'test' or 'test.asdf'.
Recommendations For osCommerce version 2.3.4.1, consider updating the '.htaccess' file in the catalog/images/ directory to include additional rules that handle files with no extension or unrecognized extensions, preventing HTML execution. As a temporary workaround, restrict access to the catalog/images/ directory to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-18965

Produtos afetados

Oscommerce