{"id":"CVE-2009-20006","title":"osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php)","summary":"osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access contr…","severity":"none","cwe":["CWE-434"],"published":"2025-09-16","updated":"2026-10-01","sourceUpdated":"2026-10-01T23:10:00.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2009-20006","references":[{"url":"https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/oscommerce_filemanager.rb","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/16899","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/9556","label":"disclosure@vulncheck.com"},{"url":"https://www.oscommerce.com/","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/oscommerce-arbitrary-php-code-execution","label":"disclosure@vulncheck.com"},{"url":"https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/oscommerce_filemanager.rb","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.exploit-db.com/exploits/16899","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.exploit-db.com/exploits/9556","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.01225,"epssPercentile":0.67711,"exploits":{"metasploit":["exploit/unix/webapp/oscommerce_filemanager"],"checkedAt":"2026-10-02T00:05:28.622Z"},"exploitAvailable":true,"ingestedAt":"2026-10-02T00:04:54.713Z","slug":"CVE-2009-20006","body":"## Overview\n\nosCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}