PT-2019-9607 · Oscommerce · Oscommerce

Hexifeo

·

Publicado

2019-08-22

·

Atualizado

2019-08-29

·

CVE-2018-18572

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions osCommerce version 2.3.4.1
Description The issue arises from an incomplete '.htaccess' file for blacklist filtering on the product page, which fails to prevent the execution of files with the '.pht' extension. This allows remote authenticated administrators to upload '.pht' files, leading to arbitrary PHP code execution. The exploitation occurs via the "/catalog/admin/categories.php?cPath=&action=new product" API endpoint, specifically by manipulating the cPath and action variables.
Recommendations For osCommerce version 2.3.4.1, update the '.htaccess' file to include the '.pht' extension in the blacklist filter to prevent arbitrary PHP code execution. As a temporary workaround, consider restricting access to the "/catalog/admin/categories.php" API endpoint for authenticated administrators until a patch is available.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18572

Produtos afetados

Oscommerce