SB2018110623 - Multiple vulnerabilities in osCommerce oscommerce2



SB2018110623 - Multiple vulnerabilities in osCommerce oscommerce2

Published: November 6, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018110623
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2018-18964)

The vulnerability allows a remote privileged user to manipulate data.

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg extension.


2) Input validation error (CVE-ID: CVE-2018-18965)

The vulnerability allows a remote privileged user to manipulate data.

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename).


Remediation

Install update from vendor's website.