CORE IMPACT v9 - Exploits Update (Wed Jul 29 2009)
Zen Cart record_company Remote Code Execution Exploit
Exploits/Remote Code Execution [Linux]
Wed Jul 29 2009
Zen Cart is prone to a vulnerability that attackers can leverage to execute arbitrary code. This issue occurs in the 'admin/record_company.php' script. Specifically, the application fails to sufficiently sanitize user-supplied input to the 'frmdt_content' parameter of the 'record_company_image' array.
Exploits Vulnerabiltiy: NOCVE-9999-38922











