PT-2006-5107 · Oscommerce · Oscommerce
Published
2006-08-23
·
Updated
2017-07-20
·
CVE-2006-4298
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
osCommerce versions prior to 2.2 Milestone 2 060817
Description
The issue allows remote attackers to determine the existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1)
tep cache also purchased, (2) tep cache manufacturers box, and (3) tep cache categories box functions.Recommendations
For osCommerce versions prior to 2.2 Milestone 2 060817, update to version 2.2 Milestone 2 060817 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oscommerce