---
id: CVE-2009-20006
title: >-
  osCommerce versions up to and including 2.2 RC2a contain a vulnerability in
  its administrative file manager utility (admin/file_manager.php)
summary: >-
  osCommerce versions up to and including 2.2 RC2a contain a vulnerability in
  its administrative file manager utility (admin/file_manager.php). The
  interface allows file uploads and edits without sufficient input validation or
  access contr…
severity: none
cwe:
  - CWE-434
published: '2025-09-16'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T23:10:00.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2009-20006'
references:
  - url: >-
      https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/oscommerce_filemanager.rb
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/16899'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/9556'
    label: disclosure@vulncheck.com
  - url: 'https://www.oscommerce.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/oscommerce-arbitrary-php-code-execution
    label: disclosure@vulncheck.com
  - url: >-
      https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/oscommerce_filemanager.rb
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.exploit-db.com/exploits/16899'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.exploit-db.com/exploits/9556'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.01225
epssPercentile: 0.67711
exploits:
  metasploit:
    - exploit/unix/webapp/oscommerce_filemanager
  checkedAt: '2026-10-02T00:05:28.622Z'
exploitAvailable: true
ingestedAt: '2026-10-02T00:04:54.713Z'
---

## Overview

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
