PT-2006-3431 · Squirrelcart · Squirrelcart

Olibekas

·

Published

2006-05-19

·

Updated

2024-02-14

·

CVE-2006-2483

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Squirrelcart versions 2.2.2 and earlier
Description A remote file inclusion issue allows attackers to execute arbitrary PHP code via a URL in the cart isp root parameter in the cart content.php file.
Recommendations For Squirrelcart versions 2.2.2 and earlier, update to a version later than 2.2.2 to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2006-2483

Affected Products

Squirrelcart