Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-20006

Опубликовано: 16 сент. 2025
Источник: nvd
EPSS Средний

Описание

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

EPSS

Процентиль: 99%
0.69505
Средний

Дефекты

CWE-434

Связанные уязвимости

github
5 месяцев назад

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

EPSS

Процентиль: 99%
0.69505
Средний

Дефекты

CWE-434