High severity7.2NVD Advisory· Published Sep 11, 2017· Updated Jun 17, 2026
CVE-2015-9227
CVE-2015-9227
Description
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3= 1.2.8+ 2 more
- (no CPE)range: = 1.2.8
- cpe:2.3:a:alegrocart:alegrocart:1.2.8:*:*:*:*:*:*:*
- (no CPE)range: 1.2.8
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/134361/AlegroCart-1.2.8-Local-Remote-File-Inclusion.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2015/Nov/67nvdExploitMailing ListThird Party Advisory
- blog.curesec.com/article/blog/AlegroCart-128-LFIRFI-102.htmlnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/38728/nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.