Phase:PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
ReferencesBUGTRAQ:Sunday, June 16, 2002 PHP source injection in osCommerce | URL:http://online.securityfocus.com/archive/1/277312 | CONFIRM:http://www.oscommerce.com/about.php/news,72 | BID:5037 | URL:http://www.securityfocus.com/bid/5037 | XF:oscommerce-inc
Votes:Assigned (Thursday, July 14, 2005)
Comments:None (candidate not yet proposed)
F7: