CVE Database
/

CVE-2009-20006

Back to search

CVE-2009-20006

Published: Sep 16, 2025

Modified: May 15, 2026

PUBLISHED

Description

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

VendorProductVersions

osCommerce

osCommerce

affected
0 - <= 2.2 RC2a

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now