Vulnerabilities > CVE-2006-5190 - Cross-Site Scripting vulnerability in osCommerce

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
oscommerce
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.

Exploit-Db

  • descriptionosCommerce 2.2 admin/specials.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28754.txt
    idEDB-ID:28754
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28754/
    titleosCommerce 2.2 admin/specials.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/currencies.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28746.txt
    idEDB-ID:28746
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28746/
    titleosCommerce 2.2 admin/currencies.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/reviews.php page Parameter XSS. CVE-2006-5190 . Webapps exploit for php platform
    fileexploits/php/webapps/28753.txt
    idEDB-ID:28753
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28753/
    titleosCommerce 2.2 admin/reviews.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/manufacturers.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28748.txt
    idEDB-ID:28748
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28748/
    titleosCommerce 2.2 admin/manufacturers.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/stats_products_viewed.php page Parameter XSS. CVE-2006-5190 . Webapps exploit for php platform
    fileexploits/php/webapps/28756.txt
    idEDB-ID:28756
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28756/
    titleosCommerce 2.2 admin/stats_products_viewed.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/zones.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28759.txt
    idEDB-ID:28759
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28759/
    titleosCommerce 2.2 admin/zones.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/products_attributes.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    idEDB-ID:28751
    last seen2016-02-03
    modified2006-10-04
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28751/
    titleosCommerce 2.2 admin/products_attributes.php page Parameter XSS
  • descriptionosCommerce 2.2 admin/languages.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28747.txt
    idEDB-ID:28747
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28747/
    titleosCommerce 2.2 admin/languages.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/products_expected.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28752.txt
    idEDB-ID:28752
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28752/
    titleosCommerce 2.2 admin/products_expected.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/banner_manager.php page Parameter XSS. CVE-2006-5190 . Webapps exploit for php platform
    fileexploits/php/webapps/28743.txt
    idEDB-ID:28743
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28743/
    titleosCommerce 2.2 admin/banner_manager.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/tax_rates.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28758.txt
    idEDB-ID:28758
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28758/
    titleosCommerce 2.2 admin/tax_rates.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/banner_statistics.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28744.txt
    idEDB-ID:28744
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28744/
    titleosCommerce 2.2 admin/banner_statistics.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/tax_classes.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28757.txt
    idEDB-ID:28757
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28757/
    titleosCommerce 2.2 admin/tax_classes.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/newsletters.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28749.txt
    idEDB-ID:28749
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28749/
    titleosCommerce 2.2 admin/newsletters.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/countries.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28745.txt
    idEDB-ID:28745
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28745/
    titleosCommerce 2.2 admin/countries.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/orders_status.php page Parameter XSS. CVE-2006-5190. Webapps exploit for php platform
    fileexploits/php/webapps/28750.txt
    idEDB-ID:28750
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28750/
    titleosCommerce 2.2 admin/orders_status.php page Parameter XSS
    typewebapps
  • descriptionosCommerce 2.2 admin/stats_products_purchased.php page Parameter XSS². CVE-2006-5190 . Webapps exploit for php platform
    fileexploits/php/webapps/28755.txt
    idEDB-ID:28755
    last seen2016-02-03
    modified2006-10-04
    platformphp
    port
    published2006-10-04
    reporterLostmon
    sourcehttps://www.exploit-db.com/download/28755/
    titleosCommerce 2.2 admin/stats_products_purchased.php page Parameter XSS
    typewebapps