CVE-2018-18966

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
4
MEDIUM
Affected
1
PROJECT

Description

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.

osCommerce Online Merchant v2.x
GitHubGitHub
281