Vulnerabilities > Oscommerce > Oscommerce > 1.0.4.0

DATE CVE VULNERABILITY TITLE RISK
2022-08-18 CVE-2022-35212 Cross-site Scripting vulnerability in Oscommerce
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().
network
low complexity
oscommerce CWE-79
6.1
2020-10-28 CVE-2020-27976 OS Command Injection vulnerability in Oscommerce
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely.
network
low complexity
oscommerce CWE-78
critical
9.8
2020-10-28 CVE-2020-27975 Cross-Site Request Forgery (CSRF) vulnerability in Oscommerce
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
network
low complexity
oscommerce CWE-352
8.8