vendor:
osCommerce
by:
Unknown
7.5
CVSS
HIGH
Remote File Upload and File Disclosure
434
CWE
Product Name: osCommerce
Affected Version From: osCommerce 2.2
Affected Version To: osCommerce 2.3.1
Patch Exists: YES
Related CWE: CVE-2012-0883
CPE: a:oscommerce:oscommerce
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ibm-http_server-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/hpsmh-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-de2bc01f-dc44-11e1-9f4d-002354ed89bc/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-0883/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2012-0883/
Platforms Tested:
2012
osCommerce Remote File Upload and File Disclosure Vulnerability
osCommerce is prone to a remote file upload and a file disclosure vulnerability. The issues occur because the application fails to adequately sanitize user-supplied input. An attacker can exploit these issues to upload a file and obtain an arbitrary file's content; other attacks are also possible.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user-supplied input before processing it.