Vulnerabilities (CVE)

Filtered by vendor Oscommerce Subscribe
Filtered by product Php Point Of Sale
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1477 1 Oscommerce 1 Php Point Of Sale 2024-04-11 7.5 HIGH N/A
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation