CVE-2015-8352: Path Traversal
Published Aug 24, 2017
·Updated
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.
Affected Software
1 affected component
Zen-cart Zen Cart=1.5.4
Remediation
Patch Available
Event History
Aug 24, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8352?
CVE-2015-8352 has a medium severity rating due to its potential to allow unauthorized file inclusion.
2
How do I fix CVE-2015-8352?
To fix CVE-2015-8352, you should update Zen Cart to a version that addresses this vulnerability.
3
Who is affected by CVE-2015-8352?
CVE-2015-8352 affects users running Zen Cart version 1.5.4.
4
How does CVE-2015-8352 work?
CVE-2015-8352 exploits a directory traversal vulnerability allowing attackers to include arbitrary local files through manipulated parameters.
5
What should I do if I am affected by CVE-2015-8352?
If you are affected by CVE-2015-8352, immediately apply the security patch or upgrade Zen Cart to mitigate the risks.