Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2638
CVE-2004-2638
Description
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.
Affected products
1- cpe:2.3:a:oscommerce:oscommerce:1.5.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/11473nvdPatchVendor Advisory
- secwatch.org/advisories/1007857nvdPatchVendor Advisory
- www.osvdb.org/5717nvd
- www.securityfocus.com/bid/10235nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16009nvd
News mentions
0No linked articles in our index yet.