PT-2018-14749 · Oscommerce · Oscommerce

Hexifeo

·

Publicado

2018-11-06

·

Atualizado

2020-08-24

·

CVE-2018-18966

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions osCommerce version 2.3.4.1
Description The issue concerns an incomplete '.htaccess' file for blacklist filtering in the product page of osCommerce. Specifically, the .htaccess file in the catalog/images/ directory bans the html extension, but Internet Explorer can render HTML elements in a .eml file.
Recommendations For osCommerce version 2.3.4.1, consider updating the .htaccess file in the catalog/images/ directory to properly handle .eml files and prevent the rendering of HTML elements within them. As a temporary workaround, restrict access to the catalog/images/ directory to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-18966

Produtos afetados

Oscommerce