PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.
References
Configurations
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://cpcommerce.org/forums/index.php?board=2%3Baction=display%3Bthreadid=864 - | |
References | () http://securityreason.com/securityalert/3301 - | |
References | () http://www.securiteam.com/unixfocus/6H00E2K8KG.html - | |
References | () http://www.securityfocus.com/archive/1/341757 - | |
References | () http://www.securityfocus.com/bid/8851 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/13457 - |
07 Nov 2023, 01:56
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:47
NVD link : CVE-2003-1500
Mitre link : CVE-2003-1500
CVE.ORG link : CVE-2003-1500
JSON object : View
Products Affected
cpcommerce
- cpcommerce
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')