Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?Need help customizing or designing scripts?Please contact us via the Contact Us option for further details and pricing.
DESCRIPTION: A vulnerability has been discovered in Zen Cart, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is confirmed in version 1.3.8a (full fileset 12112007). Other versions may also be affected.
The vulnerability is caused due to the application not properly restricting access to the administration panel. This can be exploited to access certain administrative functions, which can used to e.g. conduct SQL injection attacks and upload and execute arbitrary PHP code.
Note: Successful exploitation requires that the "admin" folder was not correctly renamed during the installation process.