First published: Tue Nov 06 2018(Updated: )
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OSCommerce Online Merchant | =2.3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this osCommerce issue is CVE-2018-18964.
The severity level of CVE-2018-18964 is medium.
This vulnerability impacts osCommerce 2.3.4.1 by allowing the execution of HTML content in certain extensions.
The osCommerce Online Merchant version 2.3.4.1 is affected by CVE-2018-18964.
Yes, a fix for CVE-2018-18964 is available. Please refer to the provided reference URL for more information.