CVE-2008-6877
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in admin/includes/initsystem.php in Zen Cart 1.3.8 and 1.3.8a, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the loader_file parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths.
** DISPUTADA ** Vulnerabilidad de salto de directorio en admin/includes/initsystem.php en Zen Cart v1.3.8 y v1.3.8a, cuando .htaccess no esta soportado, lo que permite a atacantes remotos incluir y ejecutar ficheros locales de forma arbitraria a través de .. (punto punto) en el parámetro "loader_file". NOTA: El vendedor no esta de acuerdo con este hecho, "den el peor de los casos la explotación de esta vulnerabilidad solo muestro algunos ficheros locales".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-07-27 CVE Reserved
- 2009-07-27 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-08-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/46912 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.attrition.org/pipermail/vim/2008-July/002028.html | 2024-08-07 | |
http://www.securityfocus.com/bid/30179 | 2024-08-07 | |
http://www.zen-cart.com/forum/showthread.php?t=102802 | 2024-08-07 | |
https://www.exploit-db.com/exploits/6038 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/31039 | 2024-05-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zen Cart Search vendor "Zen Cart" | Zen Cart Search vendor "Zen Cart" for product "Zen Cart" | 1.3.8 Search vendor "Zen Cart" for product "Zen Cart" and version "1.3.8" | - |
Affected
| ||||||
Zen Cart Search vendor "Zen Cart" | Zen Cart Search vendor "Zen Cart" for product "Zen Cart" | 1.3.8a Search vendor "Zen Cart" for product "Zen Cart" and version "1.3.8a" | - |
Affected
|