Description
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.
Remediation
References
Related Vulnerabilities
phpMyAdmin Other Vulnerability (CVE-2007-0204)
WordPress Plugin iThemes Exchange:Simple WP Ecommerce Cross-Site Scripting (1.11.18)
Oracle Database Server CVE-2010-0892 Vulnerability (CVE-2010-0892)
Jenkins Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2024-47803)
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-5954)