CVE-2015-2965: Path Traversal
Published Jun 28, 2015
·Updated
Directory traversal vulnerability in osCommerce Japanese 2.2ms1j-R8 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
Affected Software
1 affected component
osCommerce oscommerce<=2.2ms1j-r8
Event History
Jun 28, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2965?
CVE-2015-2965 has a medium severity rating due to its potential to allow unauthorized file access.
2
How do I fix CVE-2015-2965?
To fix CVE-2015-2965, upgrade to osCommerce version 2.2ms1j-R9 or later.
3
Who is affected by CVE-2015-2965?
CVE-2015-2965 affects remote authenticated administrators of osCommerce versions 2.2ms1j-R8 and earlier.
4
What kind of attack can exploit CVE-2015-2965?
CVE-2015-2965 can be exploited through directory traversal attacks to read arbitrary files on the server.
5
Is there a known workaround for CVE-2015-2965?
There is no widely reported workaround for CVE-2015-2965 other than upgrading to a secure version.