CVE-2009-1936

_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cpcommerce:cpcommerce:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cpcommerce:cpcommerce:1.2.2:*:*:*:*:*:*:*

Information

Published : 2009-06-05 11:30

Updated : 2017-09-28 18:34


NVD link : CVE-2009-1936

Mitre link : CVE-2009-1936


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

cpcommerce

  • cpcommerce