← Back

Cpcommerce Project

cpcommerce_project

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Cpcommerce
cpcommerce

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpcommerce Project
1Cpcommerce
Apr 23, 2026
Jun 5, 2009
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion...Show more
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.Show less