Description
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-10670 | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file. |
References
| Link | Providers |
|---|---|
| https://github.com/osCommerce/oscommerce2/issues/631 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:23:08.581Z
Reserved: 2018-11-05T00:00:00.000Z
Link: CVE-2018-18966
No data.
Status : Modified
Published: 2018-11-06T04:29:00.317
Modified: 2024-11-21T03:56:57.797
Link: CVE-2018-18966
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD