Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
| Software | From | Fixed in |
|---|---|---|
| zen-cart / zen_cart | 1.2.4.1 | 1.2.4.1.x |
| zen-cart / zen_cart | 1.2.1d | 1.2.1d.x |
| zen-cart / zen_cart | 1.2.3d | 1.2.3d.x |
| zen-cart / zen_cart | - | 1.2.6d.x |
| zen-cart / zen_cart | 1.1.3 | 1.1.3.x |
| zen-cart / zen_cart | 1.1.0 | 1.1.0.x |
| zen-cart / zen_cart | 1.2.1-patch1 | 1.2.1-patch1.x |
| zen-cart / zen_cart | 1.2.0d | 1.2.0d.x |
| zen-cart / zen_cart | 1.2.4d | 1.2.4d.x |
| zen-cart / zen_cart | 1.2.5d | 1.2.5d.x |
| zen-cart / zen_cart | 1.2.2d | 1.2.2d.x |