CVE-2008-6877 | Zen Cart 1.3.8 htaccess initsystem.php loader_file path traversal (EDB-6038 / BID-30179)
A vulnerability, which was classified as critical, has been found in Zen Cart 1.3.8. This issue affects some unknown processing of the file admin/includes/initsystem.php of the component htaccess. The manipulation of the argument loader_file leads to path traversal.
The identification of this vulnerability is CVE-2008-6877. The attack may be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.