CVE-2018-18966

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
References
Link Resource
https://github.com/osCommerce/oscommerce2/issues/631 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:oscommerce:online_merchant:2.3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-11-06 04:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-18966

Mitre link : CVE-2018-18966

CVE.ORG link : CVE-2018-18966


JSON object : View

Products Affected

microsoft

  • internet_explorer

oscommerce

  • online_merchant

NetmanageIT Website NetmanageIT OSINT Web NetmanageIT OpenCTI NetmanageIT PDF Tools NetmanageIT CVE Database NetmanageIT CTO Corner Blog NetmanageIT CTO Corner Blog NetmanageIT Password Pusher NetmanageIT Internet Health and Latency Dashboard NetmanageIT Internet Health and Latency Dashboard NetmanageIT Ubuntu Mirror 10Gbps Copyright OpenCVE 2024