CVE-2004-2638: High severity osCommerce oscommerce vulnerability
Published Dec 31, 2004
·Updated
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the inlogin parameter to a non-zero value.
Affected Software
1 affected component
osCommerce oscommerce=1.5.1
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Dec 5, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2638?
CVE-2004-2638 is considered a high-severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2004-2638?
To fix CVE-2004-2638, update your osCommerce installation to a patched version that addresses this vulnerability.
3
Who is affected by CVE-2004-2638?
CVE-2004-2638 affects users of osCommerce version 1.5.1.
4
What type of vulnerability is CVE-2004-2638?
CVE-2004-2638 is classified as a remote file inclusion vulnerability.
5
What can attackers do with CVE-2004-2638?
Attackers exploiting CVE-2004-2638 can potentially access sensitive files in the "admin/" directory.