← Back to browse · API

CVE-2009-1936

Severity
CRITICAL
CVSS
9.8
EPSS
0.42223
Risk score
53.98
CISA KEV
No
PoC
No
Published
2009-06-05
Modified
2025-01-21
First seen
2026-08-07
Aliases
EUVD-2009-1931, GHSA-492M-HH57-3GV9
Products
n/a:n/a n/a
Sources
euvd EUVD-2009-1931

Description

_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.

References