Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
Apache 2.x version older than 2.2.10
Oracle Application Server Other Vulnerability (CVE-2002-1632)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10186)
PHP Other Vulnerability (CVE-2006-1494)
WordPress Plugin SlideDeck 2 Lite Responsive Content Slider Local/Remote File Inclusion (2.3.3)