CVE-2018-18966
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
- Affected products
- Oscommerce
- Oscommerce Online Merchant
- = 2.3.4.1
- CVSS 3.0
- 4.9 MEDIUM
- EPSS
- 1.0% (61th percentile)
- NVD status
- Modified
- Published
- 2018-11-06
CVE-2018-18966 at NVD
1 known exploit for CVE-2018-18966
Proof-of-concept code and exploit modules indexed by Sploitus