vendor:
Oscommerce Online Merchant
by:
MasterGipy
7,5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: Oscommerce Online Merchant
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:oscommerce:oscommerce_online_merchant
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Oscommerce Online Merchant v2.2 – Remote File Upload
A vulnerability exists in Oscommerce Online Merchant v2.2 which allows an attacker to upload malicious files to the server. The vulnerable file is /admin/file_manager.php. An attacker can exploit this vulnerability by sending a malicious file to the server using a specially crafted HTML form.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of Oscommerce Online Merchant.