CVE-2009-2255: Medium severity zen cart vulnerability
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/recordcompany.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the recordcompanyimage parameter in conjunction with a PATHINFO of passwordforgotten.php, then accessing this file via a direct request to the file in images/.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2255?
CVE-2009-2255 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2009-2255?
To fix CVE-2009-2255, ensure you upgrade to Zen Cart version 1.3.9 or later, which includes the necessary security patches.
Which versions of Zen Cart are affected by CVE-2009-2255?
CVE-2009-2255 affects Zen Cart versions 1.3.8a, 1.3.8, and earlier versions down to 1.1.0.
Can CVE-2009-2255 allow unauthorized access to my Zen Cart admin panel?
Yes, CVE-2009-2255 can allow remote attackers to access the admin panel without proper authentication.
What are the potential impacts of CVE-2009-2255 on my website?
The potential impacts of CVE-2009-2255 include unauthorized code execution, data compromise, and complete system takeover.