Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Oscommerce | Oscommerce | 2.1 (including) | 2.1 (including) |
| Oscommerce | Oscommerce | 2.2_cvs (including) | 2.2_cvs (including) |
| Oscommerce | Oscommerce | 2.2_ms1 (including) | 2.2_ms1 (including) |
| Oscommerce | Oscommerce | 2.2_ms2 (including) | 2.2_ms2 (including) |
| Oscommerce | Oscommerce | 2.2_ms3 (including) | 2.2_ms3 (including) |