OSCommerce远程文件包含漏洞

漏洞信息详情

OSCommerce远程文件包含漏洞

漏洞简介

osCommerce 2.1版本存在PHP文件包含漏洞。该漏洞借助include_once.php的include_file参数执行任意命令。

漏洞公告

Reportedly, exploitation of this type of vulnerability is not possible unless both ‘allow_url_fopen’ and ‘register_globals’ are enabled in the local site PHP configuration.
It is good practice to disable any unneeded options.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: www.oscommerce.com
链接:http://www.oscommerce.com/about.php/news,72

来源: BID
名称: 5037
链接:http://www.securityfocus.com/bid/5037

来源: XF
名称: oscommerce-include-remote-files(9369)
链接:http://www.iss.net/security_center/static/9369.php

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享