vendor:
Zen Cart
by:
Salvatore Fresta aka Drosophila
7,5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Zen Cart
Affected Version From: 1.3.9h
Affected Version To: 1.3.9h
Patch Exists: NO
Related CWE: N/A
CPE: a:zencart:zen_cart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Zen Cart 1.3.9h Local File Inclusion Vulnerability
Input passed to the "loader_file" parameter in includes/initsystem.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal attacks. Successful exploitation requires that register_globals is set to On.
Mitigation:
No fix.