Vulnerabilities > Oscommerce > Online Merchant

DATE CVE VULNERABILITY TITLE RISK
2018-11-06 CVE-2018-18966 Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
network
low complexity
oscommerce microsoft
4.0
2018-11-06 CVE-2018-18965 Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
network
low complexity
oscommerce
4.0
2018-11-06 CVE-2018-18964 Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
network
low complexity
oscommerce
4.0
2015-01-13 CVE-2014-10033 SQL Injection vulnerability in Oscommerce Online Merchant
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.
network
low complexity
oscommerce CWE-89
6.5
2012-09-19 CVE-2012-2991 The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
network
low complexity
oscommerce paypal
5.0
2012-05-27 CVE-2012-2935 Cross-Site Scripting vulnerability in Oscommerce Online Merchant
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different vulnerability than CVE-2012-1059.
network
oscommerce CWE-79
4.3
2012-05-27 CVE-2012-1792 Cross-Site Scripting vulnerability in Oscommerce Online Merchant
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the name parameter to oscommerce/index.php, which is not properly handled in an error message.
network
high complexity
oscommerce CWE-79
2.6
2012-02-14 CVE-2012-1059 Cross-Site Scripting vulnerability in Oscommerce Online Merchant 3.0.2
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.
network
oscommerce CWE-79
4.3
2012-01-26 CVE-2012-0312 Cross-Site Scripting vulnerability in Oscommerce Online Merchant and Oscommerce
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
oscommerce CWE-79
4.3
2008-10-28 CVE-2008-4765 SQL Injection vulnerability in Oscommerce Poll Booth 2.0
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation.
network
low complexity
oscommerce CWE-89
7.5