Vulnerability Description
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zen-Cart | Zen Cart | 1.5.4 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/537129/100/0/threadedExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39017/ExploitThird Party AdvisoryVDB Entry
- https://www.htbridge.com/advisory/HTB23282ExploitPatchTechnical Description
- https://www.zen-cart.com/showthread.php?218914-Security-Patches-for-v1-5-4-NovemPatchRelease NotesVendor Advisory
- http://www.securityfocus.com/archive/1/537129/100/0/threadedExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39017/ExploitThird Party AdvisoryVDB Entry
- https://www.htbridge.com/advisory/HTB23282ExploitPatchTechnical Description
- https://www.zen-cart.com/showthread.php?218914-Security-Patches-for-v1-5-4-NovemPatchRelease NotesVendor Advisory
FAQ
What is CVE-2015-8352?
CVE-2015-8352 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.
How severe is CVE-2015-8352?
CVE-2015-8352 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-8352?
Check the references section above for vendor advisories and patch information. Affected products include: Zen-Cart Zen Cart.