First published: Tue Nov 06 2018(Updated: )
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OSCommerce Online Merchant | =2.3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-18965.
The severity level of CVE-2018-18965 is medium, with a severity value of 4.9.
The affected software for CVE-2018-18965 is osCommerce 2.3.4.1.
This vulnerability can be exploited by executing HTML code in files with no extension or unrecognized extensions.
At the moment, there is no official fix available for CVE-2018-18965. It is recommended to stay updated with the latest patches and security practices.