CVE-2004-2021 | osCommerce 2.1/2.2 Cvs/2.2 Ms1/2.2 Ms2/2.2 Ms3 file_manager.php filename path traversal (EDB-24126 / Nessus ID 17595)
A vulnerability was found in osCommerce 2.1/2.2 Cvs/2.2 Ms1/2.2 Ms2/2.2 Ms3. It has been classified as problematic. Affected is an unknown function of the file file_manager.php. The manipulation of the argument filename leads to path traversal.
This vulnerability is traded as CVE-2004-2021. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.