PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
References
Link | Resource |
---|---|
http://online.securityfocus.com/archive/1/277312 | |
http://www.oscommerce.com/about.php/news,72 | Exploit Patch Vendor Advisory |
http://www.securityfocus.com/bid/5037 | Exploit |
http://www.iss.net/security_center/static/9369.php |
Configurations
Information
Published : 2002-12-30 21:00
Updated : 2008-09-04 21:00
NVD link : CVE-2002-1991
Mitre link : CVE-2002-1991
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
oscommerce
- oscommerce