Description
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin P3 (Plugin Performance Profiler) Cross-Site Scripting (1.5.3.8)
WordPress Plugin OG Tags Cross-Site Request Forgery (2.0.1)
WordPress Plugin WordPress File Upload Arbitrary File Upload (3.8.5)
Serendipity Other Vulnerability (CVE-2005-1450)
Oracle Database Server CVE-2009-1965 Vulnerability (CVE-2009-1965)