CVE-2007-1477

Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation
Configurations

Configuration 1 (hide)

cpe:2.3:a:oscommerce:php_point_of_sale:1.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:28

Type Values Removed Values Added
References () http://attrition.org/pipermail/vim/2007-April/001564.html - () http://attrition.org/pipermail/vim/2007-April/001564.html -
References () http://securityreason.com/securityalert/2426 - () http://securityreason.com/securityalert/2426 -
References () http://www.securityfocus.com/archive/1/462970/100/0/threaded - () http://www.securityfocus.com/archive/1/462970/100/0/threaded -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/33006 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/33006 -

07 Nov 2023, 02:00

Type Values Removed Values Added
Summary ** DISPUTED ** Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation. Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation

Information

Published : 2007-03-16 21:19

Updated : 2024-11-21 00:28


NVD link : CVE-2007-1477

Mitre link : CVE-2007-1477

CVE.ORG link : CVE-2007-1477


JSON object : View

Products Affected

oscommerce

  • php_point_of_sale