Loading...
Loading...
Directory traversal vulnerability in admin/includes/initsystem.php in Zen Cart 1.3.8 and 1.3.8a, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the loader_file parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths.
July 27, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-6877
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.