Back

CVE-2005-2330

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.

Published: Jul 20, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
oscommerce oscommerce 2.2_ms2

GitHub Security Advisory GHSA-g9q2-76cm-p4jq

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 9.60%

Top 5% most likely to be exploited

Threat Score 22.9 / 100

Data Sources

NVD EPSS GitHub