CVE-2013-1891
MEDIUMOpenCart 1.4.7-1.5.5.1 - Path Traversal via Filemanager Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-1891. PoCs published by waraxe.
AI-analyzed exploit summary This is a detailed advisory describing directory traversal vulnerabilities in OpenCart's filemanager.php. It explains how insufficient sanitization of user-supplied data allows bypassing directory traversal protections via techniques like using backslashes or encoded sequences.
Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Exploits (1)
This is a detailed advisory describing directory traversal vulnerabilities in OpenCart's filemanager.php. It explains how insufficient sanitization of user-supplied data allows bypassing directory traversal protections via techniques like using backslashes or encoded sequences.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N