Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zen_cart | Zen-cart | * | 1.2.6d (including) |
Zen_cart | Zen-cart | 1.1.0 (including) | 1.1.0 (including) |
Zen_cart | Zen-cart | 1.1.3 (including) | 1.1.3 (including) |
Zen_cart | Zen-cart | 1.2.0d (including) | 1.2.0d (including) |
Zen_cart | Zen-cart | 1.2.1-patch1 (including) | 1.2.1-patch1 (including) |
Zen_cart | Zen-cart | 1.2.1d (including) | 1.2.1d (including) |
Zen_cart | Zen-cart | 1.2.2d (including) | 1.2.2d (including) |
Zen_cart | Zen-cart | 1.2.3d (including) | 1.2.3d (including) |
Zen_cart | Zen-cart | 1.2.4.1 (including) | 1.2.4.1 (including) |
Zen_cart | Zen-cart | 1.2.4d (including) | 1.2.4d (including) |
Zen_cart | Zen-cart | 1.2.5d (including) | 1.2.5d (including) |