vendor:
osCommerce
by:
daandeveloper33
7,5
CVSS
HIGH
Change Admin Pass
N/A
CWE
Product Name: osCommerce
Affected Version From: v2.2
Affected Version To: v2.2
Patch Exists: NO
Related CWE: N/A
CPE: oscommerce
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OS X 10.6.4, osCommerce v2.2 RC2A (Dutch)
2010
osCommerce v2.2 Change Admin Pass
This exploit allows an attacker to change the admin password of the admin panel of osCommerce. After the password is changed, the attacker has all admin privileges.
Mitigation:
Write protection.php and paste following code in all pages in the /admin map (except login.php): include('protection.php')