CVE-2008-6878 | Zen Cart up to 1.3.8 htaccess english.php _SESSION[language] path traversal (EDB-6038 / BID-30179)
A vulnerability, which was classified as critical, was found in Zen Cart up to 1.3.8. Affected is an unknown function of the file admin/includes/languages/english.php of the component htaccess. The manipulation of the argument _SESSION[language] leads to path traversal.
This vulnerability is traded as CVE-2008-6878. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.