osCommerce Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2002-2019 - Vulnerability Database

osCommerce Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2002-2019

High
Reference: CVE-2002-2019
Title: osCommerce Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.