PT-2002-2740 · Oscommerce · Oscommerce
Published
2002-12-31
·
Updated
2011-06-29
·
CVE-2002-2019
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
osCommerce (a.k.a. Exchange Project) version 2.1
Description
The issue allows remote attackers to execute arbitrary PHP code via the
include file parameter in the include once.php file.Recommendations
For osCommerce (a.k.a. Exchange Project) version 2.1, consider restricting access to the include once.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the
include file parameter in the affected file until the issue is resolved.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oscommerce