Looking for the vulnerability index of Invicti's legacy products?
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573) - Vulnerability Database

osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573)

Description

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.

References

Related Vulnerabilities