Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of the admin_name array parameter to admin_dir/login.php, if there is an export of an error-log entry for that invalid array index.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZenCart 安全漏洞
Vulnerability Description
ZenCart是Zen Cart团队开发的一套开源的购物车系统,它主要用于建立网上商店,可支持多种付款方式、多语言选择、网上商城批量更新等。 ZenCart 1.5.5e版本中的admin_dir/includes/classes/AdminRequestSanitizer.php文件的‘traverseStrictSanitize’函数存在安全漏洞,该漏洞源于程序没有正确的处理密钥字符串。远程攻击者可通过向‘admin_name array’参数中的无效数组索引输入代码,并将参数发送到admin_dir
CVSS Information
N/A
Vulnerability Type
N/A