Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oscommerce | Oscommerce | 2.1 (including) | 2.1 (including) |
Oscommerce | Oscommerce | 2.2_cvs (including) | 2.2_cvs (including) |
Oscommerce | Oscommerce | 2.2_ms1 (including) | 2.2_ms1 (including) |
Oscommerce | Oscommerce | 2.2_ms2 (including) | 2.2_ms2 (including) |
Oscommerce | Oscommerce | 2.2_ms3 (including) | 2.2_ms3 (including) |