CVE-2018-18964: Medium severity oscommerce php point of sale vulnerability
Published Nov 6, 2018
·Updated
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg extension.
Affected Software
1 affected component
osCommerce Online Merchant=2.3.4.1
Event History
Nov 6, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this osCommerce issue?
The vulnerability ID for this osCommerce issue is CVE-2018-18964.
2
What is the severity level of CVE-2018-18964?
The severity level of CVE-2018-18964 is medium.
3
How does this vulnerability impact osCommerce 2.3.4.1?
This vulnerability impacts osCommerce 2.3.4.1 by allowing the execution of HTML content in certain extensions.
4
What software is affected by CVE-2018-18964?
The osCommerce Online Merchant version 2.3.4.1 is affected by CVE-2018-18964.
5
Is there a fix available for CVE-2018-18964?
Yes, a fix for CVE-2018-18964 is available. Please refer to the provided reference URL for more information.