First published: Tue Nov 06 2018(Updated: )
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OSCommerce Online Merchant | =2.3.4.1 | |
Microsoft Internet Explorer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for osCommerce 2.3.4.1 is CVE-2018-18966.
The severity level of CVE-2018-18966 is medium with a value of 4.9.
osCommerce 2.3.4.1 has an incomplete .htaccess file for blacklist filtering in the 'product' page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer renders HTML elements in a .eml file.
osCommerce 2.3.4.1 is affected by CVE-2018-18966.
No, Microsoft Internet Explorer is not vulnerable to CVE-2018-18966.
You can find more information about CVE-2018-18966 at the following link: [https://github.com/osCommerce/oscommerce2/issues/631](https://github.com/osCommerce/oscommerce2/issues/631)