CVE-2006-4218: High severity Zen Cart Zen Cart vulnerability
Published Aug 17, 2006
·Updated
Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter parameter.
Affected Software
10 affected components
Zen Cart Zen Cart=1.2.0d
Zen Cart Zen Cart=1.2.1_patch1
Zen Cart Zen Cart=1.2.1d
Zen Cart Zen Cart=1.2.2d
Zen Cart Zen Cart=1.2.3d
Zen Cart Zen Cart=1.2.4.1
Zen Cart Zen Cart=1.2.4d
Zen Cart Zen Cart=1.2.5d
Zen Cart Zen Cart=1.2.6d
Zen Cart Zen Cart=1.3.0.2
Remediation
Patch Available
Event History
Aug 17, 2006
CVE Published
11:04 PM
Aug 18, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4218?
CVE-2006-4218 is rated as a medium severity vulnerability.
2
How do I fix CVE-2006-4218?
To fix CVE-2006-4218, users should upgrade to Zen Cart version 1.3.0.3 or later.
3
What systems are affected by CVE-2006-4218?
CVE-2006-4218 affects Zen Cart versions 1.3.0.2 and earlier as well as several earlier versions.
4
What kind of attacks can exploit CVE-2006-4218?
Exploitation of CVE-2006-4218 can allow remote attackers to execute arbitrary local files on the server.
5
Is CVE-2006-4218 related to directory traversal?
Yes, CVE-2006-4218 is a directory traversal vulnerability that allows unauthorized access to file system paths.