vendor:
osCommerce
by:
indoushka
8,8
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: osCommerce
Affected Version From: 1.2.1
Affected Version To: 1.2.1
Patch Exists: NO
Related CWE: N/A
CPE: oscommerce
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
osCSS 1.2.1 (REMOTE FILE UPLOAD) Vulnerabilities
A vulnerability exists in osCommerce 1.2.1 which allows an attacker to upload malicious files to the server. The vulnerability is due to insufficient validation of the file being uploaded. An attacker can exploit this vulnerability by uploading a malicious file to the server and then executing it.
Mitigation:
Ensure that all files being uploaded are properly validated and sanitized before being accepted.