cve/2018/CVE-2018-18966.md
2024-05-26 14:27:05 +02:00

702 B

CVE-2018-18966

Description

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.

POC

Reference

No PoCs from references.

Github