Remote code execution is accessible in the ./admin/ folder.
The admin folder *should* be protected by a .htaccess file similar to
osCommerce2.
Vulnerable configuration:
A there is a call to extract($_GET) so the exploit will work regardless of
register_globals. Using Linux is a very good fix for this issue.
Merry Christmas
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.