First published: Fri Dec 31 2004(Updated: )
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oscommerce Oscommerce | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2638 is considered a high-severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2004-2638, update your osCommerce installation to a patched version that addresses this vulnerability.
CVE-2004-2638 affects users of osCommerce version 1.5.1.
CVE-2004-2638 is classified as a remote file inclusion vulnerability.
Attackers exploiting CVE-2004-2638 can potentially access sensitive files in the "admin/" directory.