Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-21601 | A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An unauthenticated attacker can invoke install_4.php, submit crafted POST data, and inject arbitrary PHP code into the configure.php file. When the application later includes this file, the injected payload is executed, resulting in full server-side compromise. |
Fri, 21 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:oscommerce:online_merchant:2.3.4.1:*:*:*:*:*:*:* |
Wed, 23 Jul 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oscommerce
Oscommerce online Merchant |
|
| Vendors & Products |
Oscommerce
Oscommerce online Merchant |
Wed, 23 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An unauthenticated attacker can invoke install_4.php, submit crafted POST data, and inject arbitrary PHP code into the configure.php file. When the application later includes this file, the injected payload is executed, resulting in full server-side compromise. | |
| Title | osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution | |
| Weaknesses | CWE-434 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:03:44.222Z
Reserved: 2025-07-22T20:08:18.728Z
Link: CVE-2018-25114
Updated: 2025-07-23T14:45:54.787Z
Status : Deferred
Published: 2025-07-23T14:15:32.447
Modified: 2026-04-15T00:35:42.020
Link: CVE-2018-25114
No data.
OpenCVE Enrichment
Updated: 2025-07-23T20:19:23Z
EUVD