osCommerce allows remote attacker to include remote PHP files
| oscommerce-include-remote-files (9369) |
Description:
osCommerce could allow a remote attacker to include malicious PHP files. A remote attacker can include malicious PHP files by sending a specially-crafted request containing "include_once.php" and set the "include_file' parameter" to a malicious PHP file on a remote system. It may be possible for an attacker to use this vulnerability to gain access to other sensitive information.
Consequences:
Gain Privileges
Remedy:
No remedy available as of July 9, 2011.
References:
- BugTraq Mailing List, Sun Jun 16 2002 - 10:36:03 CDT: PHP source injection in osCommerce.
- BID-5037: OSCommerce Remote File Include Vulnerability
- CVE-2002-1991: PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
- CVE-2002-2019: PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.
Platforms Affected:
- osCommerce osCommerce Preview Release 2.1
Reported:
Jun 16, 2002
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
