Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
2006-02-15T11:06:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zen-cart | zen_cart | ≤ 1.2.6d | Yes |
Application | zen-cart | zen_cart | 1.1.0 | Yes |
Application | zen-cart | zen_cart | 1.1.3 | Yes |
Application | zen-cart | zen_cart | 1.2.0d | Yes |
Application | zen-cart | zen_cart | 1.2.1 | Yes |
Application | zen-cart | zen_cart | 1.2.1d | Yes |
Application | zen-cart | zen_cart | 1.2.2d | Yes |
Application | zen-cart | zen_cart | 1.2.3d | Yes |
Application | zen-cart | zen_cart | 1.2.4.1 | Yes |
Application | zen-cart | zen_cart | 1.2.4d | Yes |
Application | zen-cart | zen_cart | 1.2.5d | Yes |