SecBoard
Zurück zur CVE-Übersicht

CVE-2009-2255

MEDIUM(6.8)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Risk Signal Score26/100 — MITTEL
  • CVSS 6.8 — Mittel
  • EPSS 31%

EPSS-Score

31%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

6.8

Technische Schwere

Beschreibung

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with a PATH_INFO of password_forgotten.php, then accessing this file via a direct request to the file in images/.

Referenzen