CVE-2007-1477: High severity osCommerce PHP Point Of Sale vulnerability
DISPUTED Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfglanguage parameter. NOTE: this issue has been disputed by CVE, since the cfglanguage variable is configured upon proper product installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1477?
CVE-2007-1477 is classified as a moderate severity vulnerability.
How do I fix CVE-2007-1477?
To fix CVE-2007-1477, update the PHP Point Of Sale application to a version that is not affected or validate user inputs properly.
What type of attack does CVE-2007-1477 allow?
CVE-2007-1477 allows remote attackers to execute arbitrary local files through a directory traversal exploit.
Which software versions are affected by CVE-2007-1477?
CVE-2007-1477 affects PHP Point Of Sale for osCommerce version 1.1.
Is CVE-2007-1477 still a concern for current systems?
CVE-2007-1477 may still pose a risk if outdated versions of PHP Point Of Sale are in use.