Описание
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- https://medium.com/%40cupc4k3/oscommerce-v4-rce-unveiling-the-file-upload-bypass-threat-f1ac0097880cExploitThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- https://medium.com/%40cupc4k3/oscommerce-v4-rce-unveiling-the-file-upload-bypass-threat-f1ac0097880cExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:oscommerce:oscommerce:4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00016
Низкий
6.6 Medium
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 6.6
github
почти 2 года назад
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
EPSS
Процентиль: 3%
0.00016
Низкий
6.6 Medium
CVSS3
Дефекты
CWE-94