Vulnerabilities > Oscommerce > Online Merchant > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-11-06 | CVE-2018-18966 | Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. | 4.0 |
2018-11-06 | CVE-2018-18965 | Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. | 4.0 |
2018-11-06 | CVE-2018-18964 | Unspecified vulnerability in Oscommerce Online Merchant 2.3.4.1 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. | 4.0 |
2015-01-13 | CVE-2014-10033 | SQL Injection vulnerability in Oscommerce Online Merchant SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action. | 6.5 |
2012-09-19 | CVE-2012-2991 | The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self. | 5.0 |
2012-05-27 | CVE-2012-2935 | Cross-Site Scripting vulnerability in Oscommerce Online Merchant Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different vulnerability than CVE-2012-1059. | 4.3 |
2012-02-14 | CVE-2012-1059 | Cross-Site Scripting vulnerability in Oscommerce Online Merchant 3.0.2 Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module. | 4.3 |
2012-01-26 | CVE-2012-0312 | Cross-Site Scripting vulnerability in Oscommerce Online Merchant and Oscommerce Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |