cubecart / v6

CubeCart Version 6
https://cubecart.com
71 stars 58 forks source link

Path traversal / LFI may lead to RCE #3586

Closed abrookbanks closed 2 months ago

abrookbanks commented 2 months ago

In the admin panel, parameters such as _g and node are used to construct the path to include .inc.php files and execute PHP code. A malicious user with the ability to upload .inc.php files anywhere on the server can exploit a path traversal vulnerability to include them and execute malicious code.

Risk: Low

abrookbanks commented 2 months ago

Many thanks Julio Araujo.