Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
PHP Resource Management Errors Vulnerability (CVE-2007-3806)
WordPress Plugin PickPlugins Product Slider for WooCommerce Cross-Site Scripting (1.13.21)
WordPress Plugin Filedownload 'download.php' Local File Disclosure (0.1)
WebLogic CVE-2023-21839 Vulnerability (CVE-2023-21839)
MongoDb Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-20803)