Back

CVE-2002-1991

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
oscommerce oscommerce 2.1

GitHub Security Advisory GHSA-rp2x-mrrh-4c4r

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 7.46%

Top 6% most likely to be exploited

Threat Score 32.2 / 100

Data Sources

NVD EPSS GitHub