This application requires Javascript for optimal performance.

osCommerce.Arbitrary.File.Upload

Release Date

Nov 03, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit an arbitrary file upload vulnerability in osCommerce.

The vulnerability is caused by an error that occurs when the vulnerable software handles file upload without authentication. It allows a remote attacker to execute arbitrary code via sending a crafted web page.

Affected Products

osCommerce Online Merchant 2.2 RC2a

Recommended Actions

Refer to the vendor's web site for suggested workaround.

Coverage

IPS
VCM

Reference/s

http://www.milw0rm.com/exploits/9556

Reference: VID-17845