CVE-2009-2255
Zen Cart <1.3.8a-1.3.8 - RCE
Title source: llmDescription
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with a PATH_INFO of password_forgotten.php, then accessing this file via a direct request to the file in images/.
Exploits (1)
References (7)
Scores
EPSS
0.3518
EPSS Percentile
97.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (9)
zen-cart/zen_cart
< 1.3.8a
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
zen-cart/zen_cart
Timeline
Published
Jun 30, 2009
Tracked Since
Feb 18, 2026