osCommerce Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2002-1991 - Vulnerability Database

osCommerce Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2002-1991

High
Reference: CVE-2002-1991
Title: osCommerce Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.