Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zen_cart | Zen_cart | 1.2.0d (including) | 1.2.0d (including) |
Zen_cart | Zen_cart | 1.2.1_patch1 (including) | 1.2.1_patch1 (including) |
Zen_cart | Zen_cart | 1.2.1d (including) | 1.2.1d (including) |
Zen_cart | Zen_cart | 1.2.2d (including) | 1.2.2d (including) |
Zen_cart | Zen_cart | 1.2.3d (including) | 1.2.3d (including) |
Zen_cart | Zen_cart | 1.2.4.1 (including) | 1.2.4.1 (including) |
Zen_cart | Zen_cart | 1.2.4d (including) | 1.2.4d (including) |
Zen_cart | Zen_cart | 1.2.5d (including) | 1.2.5d (including) |
Zen_cart | Zen_cart | 1.2.6d (including) | 1.2.6d (including) |
Zen_cart | Zen_cart | 1.3.0.2 (including) | 1.3.0.2 (including) |