First published: Thu Aug 17 2006(Updated: )
PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zen Cart | <=1.3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4215 has a medium severity rating due to its potential to allow remote code execution.
To fix CVE-2006-4215, you should upgrade Zen Cart to version 1.3.0.3 or later and disable register_globals.
CVE-2006-4215 affects Zen Cart versions 1.3.0.2 and earlier when register_globals is enabled.
CVE-2006-4215 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
Yes, CVE-2006-4215 can be exploited remotely without authentication if register_globals is enabled.