First published: Tue Dec 31 2002(Updated: )
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
osCommerce Poll Booth | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2019 is considered critical due to its potential for remote code execution.
To fix CVE-2002-2019, upgrade to a patched version of osCommerce that addresses the remote file inclusion vulnerability.
CVE-2002-2019 affects users running osCommerce version 2.1.
CVE-2002-2019 is classified as a remote file inclusion vulnerability.
Attackers exploiting CVE-2002-2019 can execute arbitrary PHP code on the affected server.