Published:2012/01/20 Last Updated:2012/01/20
JVN#38216398
osCommerce vulnerable to directory traversal
Overview
osCommerce contains a directory traversal vulnerability.
Products Affected
- osCommerce 2.2 MS1 Japanese version R8 and earlier
- osCommerce Online Merchant versions prior to v2.3.1
Description
osCommerce is an open source system for creating shopping websites. osCommerce contains a directory traversal vulnerability.
Impact
A remote attacker may access arbitrary files on the server.
Solution
Update the software
Update to the latest version according to the information provided by the developer.
Vendor Status
Vendor | Link |
osCommerce Japanese Localization Project | osCommerce for creating shopping websites - Support Documents (Japanese only) |
osCommerce Japanese version - downloads (Japanese only) | |
[Important] About cross-site scripting vulnerability (Japanese only) | |
osCommerce | Downloads |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2012.01.20
Measures | Conditions | Severity |
---|---|---|
Access Required | can be attacked over the Internet using packets |
|
Authentication | anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls) |
|
Credit
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2005-2330 |
JVN iPedia |
JVNDB-2012-000006 |