CPCommerce Functions Remote File Include Vulnerability
BID:8851
Info
CPCommerce Functions Remote File Include Vulnerability
| Bugtraq ID: | 8851 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2003 12:00AM |
| Updated: | Oct 19 2003 12:00AM |
| Credit: | Discovery is credited to Astharot of Zone-H. |
| Vulnerable: |
cpCommerce cpCommerce 0.5 f |
| Not Vulnerable: | |
Discussion
CPCommerce Functions Remote File Include Vulnerability
cpCommerce may allow remote users to influence the include path for PHP scripts. This could be exploited to include a malicious script that is hosted on an attacker-controlled server, allowing for execution of arbitrary code in the context of the web server.
cpCommerce may allow remote users to influence the include path for PHP scripts. This could be exploited to include a malicious script that is hosted on an attacker-controlled server, allowing for execution of arbitrary code in the context of the web server.
Exploit / POC
CPCommerce Functions Remote File Include Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
CPCommerce Functions Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CPCommerce Functions Remote File Include Vulnerability
References:
References:
- VULNERABILITY WARNING!!!! (cpCommerce)
- ZH2003-31SA (security advisory): file inclusion vulnerability in cpCommerce (Astharot
)