CVE-2006-4298: Medium severity osCommerce oscommerce vulnerability
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1) tepcachealsopurchased, (2) tepcachemanufacturersbox, and (3) tepcachecategoriesbox functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4298?
CVE-2006-4298 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2006-4298?
To mitigate CVE-2006-4298, you should upgrade your osCommerce installation to version 2.2 Milestone 2 060817 or later.
What versions of osCommerce are affected by CVE-2006-4298?
CVE-2006-4298 affects osCommerce versions prior to 2.2 Milestone 2 060817.
What type of attack does CVE-2006-4298 enable?
CVE-2006-4298 allows remote attackers to perform directory traversal attacks that can disclose sensitive file paths.
Where can I find more information about CVE-2006-4298?
Detailed information regarding CVE-2006-4298 can be found in various cybersecurity vulnerability databases.