vendor:
Zen Cart
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Local File Inclusion Vulnerability
98
CWE
Product Name: Zen Cart
Affected Version From: 1.3.9f
Affected Version To: 1.3.9f
Patch Exists: YES
Related CWE: N/A
CPE: a:zen_ventures:zen_cart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache 2.2.11 (Win32), PHP 5.3.0, MySQL 5.1.36
2010
Zen Cart v1.3.9f (typefilter) Local File Inclusion Vulnerability
Zen Cart v1.3.9f suffers from a file inlcusion vulnerability (LFI) / file disclosure vulnerability (FD) when input passed thru the 'typefilter' parameter to index.php is not properly verified before being used to include files. This can be exploited to include files from local resources with directory traversal attacks and URL encoded NULL bytes.
Mitigation:
Upgrade to the latest version of Zen Cart