CVE-2009-2255

Zen Cart <1.3.8a-1.3.8 - RCE

Title source: llm

Description

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with a PATH_INFO of password_forgotten.php, then accessing this file via a direct request to the file in images/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by BlackH · phpwebappsphp
https://www.exploit-db.com/exploits/9004

Scores

EPSS 0.3518
EPSS Percentile 97.0%

Classification

CWE
CWE-287
Status draft

Affected Products (9)

zen-cart/zen_cart < 1.3.8a
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart

Timeline

Published Jun 30, 2009
Tracked Since Feb 18, 2026