5
CVSSv2

CVE-2005-2330

Published: 20/07/2005 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote malicious users to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

oscommerce oscommerce 2.2_ms2

Exploits

source: wwwsecurityfocuscom/bid/14294/info osCommerce is prone to an information-disclosure vulnerability An attacker could exploit this vulnerability to display the contents of any file normally readable by the webserver process Successful exploitation would result in information disclosure Information obtained could aid the attacker ...