Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v9 - Exploits Update (Wed Oct 14 2009)

osCommerce Arbitrary File Upload Exploit

Exploits/Remote File Inclusion/Known Vulnerabilities  []




• Wed Oct 14 2009
osCommerce Online Merchant 2.2 RC2a is vulnerable to an Arbitrary File Upload without the need to be authenticated. This leads to arbitrary PHP code execution in the context of the webserver. This module tries to install a RFI agent if the Web Application is vulnerable. It will fail if the webserver is not allowed to write on the document root of the vulnerable web application.

Exploits Vulnerabiltiy: NOCVE-9999-40096



< Back to Product Updates