Vulnerabilities > Oscommerce > Oscommerce

DATE CVE VULNERABILITY TITLE RISK
2008-09-22 CVE-2008-4170 Information Exposure vulnerability in Oscommerce 2.2
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
network
low complexity
oscommerce CWE-200
5.0
2008-02-12 CVE-2008-0719 SQL Injection vulnerability in Oscommerce Customer Testimonials and Oscommerce
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.
network
low complexity
oscommerce CWE-89
7.5
2006-12-14 CVE-2006-6534 Input Validation vulnerability in Oscommerce 3.0A3
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selected_box parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languages_definitions.php, or the (4) pID parameter to admin/products.php.
network
oscommerce
4.3
2006-12-14 CVE-2006-6533 Input Validation vulnerability in Oscommerce 3.0A3
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PHP files via a ..
network
low complexity
oscommerce
7.5
2006-10-10 CVE-2006-5190 Cross-Site Scripting vulnerability in osCommerce
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.
network
oscommerce
4.3
2006-08-23 CVE-2006-4298 Directory Traversal vulnerability in Oscommerce 2.2Ms220060817
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence of arbitrary files and disclose the installation path via a ..
network
low complexity
oscommerce
5.0
2006-08-23 CVE-2006-4297 SQL Injection vulnerability in Oscommerce 2.2Ms220060817
SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQL commands via id array parameters.
network
low complexity
oscommerce
7.5
2005-06-16 CVE-2005-1951 HTTP Response Splitting vulnerability in osCommerce
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.
network
low complexity
oscommerce
5.0
2005-05-02 CVE-2005-0458 Cross-Site Scripting vulnerability in Oscommerce 2.2Ms2
Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.
network
oscommerce
4.3
2004-12-31 CVE-2004-2638 Unspecified vulnerability in Oscommerce 1.5.1
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.
network
low complexity
oscommerce
7.5