Description
The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) install.txt, which allows remote attackers to obtain sensitive information, delete the database, and conduct other attacks via a direct request, different vulnerabilities than CVE-2009-4321 and CVE-2009-4322.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Advertising System PHP Object Injection (1.3.1)
WordPress Plugin WP Mobile Detector Unspecified Vulnerability (2.1)
Moodle Improper Validation of Integrity Check Value Vulnerability (CVE-2012-1170)
WordPress Plugin Essential Content Types Security Bypass (1.4)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (18.3)