osCommerce Online Merchant 2.3.4.1 contains a remote code execution caused by insecure default configuration and missing authentication in the installer workflow, letting unauthenticated attackers execute arbitrary PHP code via install_4.php, exploit requires accessible /install/ directory after installation.
id: CVE-2018-25114
info:
name: osCommerce 2.3.4.1 - Remote Code Execution
author: Suman_Kar
s
...