PT-2010-2680 · Saskia · Saskia'S Shopsystem
Published
2010-03-09
·
Updated
2017-08-17
·
CVE-2010-0957
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Saskia's Shopsystem versions beta1 and earlier
Description
A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by using directory traversal sequences in the
id parameter of the content.php file.Recommendations
For versions beta1 and earlier, consider restricting access to the content.php file until a patch is available. As a temporary workaround, avoid using the
id parameter in the content.php file to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saskia'S Shopsystem