Description
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).
Remediation
References
Related Vulnerabilities
WordPress Plugin Gravity Forms Dynamics CRM Cross-Site Scripting (1.0.7)
Oracle JRE CVE-2011-3563 Vulnerability (CVE-2011-3563)
Oracle Database Server CVE-2007-2110 Vulnerability (CVE-2007-2110)
Joomla Improper Access Control Vulnerability (CVE-2015-7899)
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573)