PT-2006-5107 · Oscommerce · Oscommerce

Published

2006-08-23

·

Updated

2017-07-20

·

CVE-2006-4298

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions osCommerce versions prior to 2.2 Milestone 2 060817
Description The issue allows remote attackers to determine the existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1) tep cache also purchased, (2) tep cache manufacturers box, and (3) tep cache categories box functions.
Recommendations For osCommerce versions prior to 2.2 Milestone 2 060817, update to version 2.2 Milestone 2 060817 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4298

Affected Products

Oscommerce