Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oscommerce | Oscommerce | 2.2_ms2 (including) | 2.2_ms2 (including) |