10
CVSSv2

CVE-2015-8352

Published: 24/08/2017 Updated: 03/05/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in Zen Cart 1.5.4 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.

Vulnerable Product Search on Vulmon Subscribe to Product

zen-cart zen cart 1.5.4

Exploits

Advisory ID: HTB23282 Product: Zen Cart Vendor: Zen Ventures, LLC Vulnerable Version(s): 154 Tested Version: 154 Advisory Publication: November 25, 2015 [without technical details] Vendor Notification: November 25, 2015 Vendor Patch: November 26, 2015 Public Disclosure: December 16, 2015 Vulnerability Type: PHP File Inclusion [CWE-98] CVE ...
Zen Cart version 154 suffers from a local file inclusion vulnerability ...