osCommerce Installer Unauthenticated Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 3 May 2018.

  1. Packet Storm

    Packet Storm Guest

    If the /install/ directory was not removed, it is possible for an unauthenticated attacker to run the "install_4.php" script, which will create the configuration file for the installation. This allows the attacker to inject PHP code into the configuration file and execute it.

    Continue reading...
     

Share This Page

Loading...