Description
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.
Remediation
References
Related Vulnerabilities
OpenSSL Resource Management Errors Vulnerability (CVE-2012-1165)
Moodle Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2024-48896)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2018-1000861)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7486)