Unrated severityNVD Advisory· Published Jul 27, 2009· Updated Jun 16, 2026
CVE-2008-6877
CVE-2008-6877
Description
Directory traversal vulnerability in admin/includes/initsystem.php in Zen Cart 1.3.8 and 1.3.8a, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the loader_file parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
6- www.attrition.org/pipermail/vim/2008-July/002028.htmlnvdExploit
- www.securityfocus.com/bid/30179nvdExploit
- www.zen-cart.com/forum/showthread.phpnvdExploit
- secunia.com/advisories/31039nvdVendor Advisory
- osvdb.org/46912nvd
- www.exploit-db.com/exploits/6038nvd
News mentions
0No linked articles in our index yet.