Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v9 - Exploits Update (Wed Jul 29 2009)

Zen Cart record_company Remote Code Execution Exploit

Exploits/Remote Code Execution  [Linux]




• Wed Jul 29 2009
Zen Cart is prone to a vulnerability that attackers can leverage to execute arbitrary code. This issue occurs in the 'admin/record_company.php' script. Specifically, the application fails to sufficiently sanitize user-supplied input to the 'frmdt_content' parameter of the 'record_company_image' array.

Exploits Vulnerabiltiy: NOCVE-9999-38922



< Back to Product Updates