Vulnerabilities > Oscommerce > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-02-03 CVE-2009-0408 Cross-Site Request Forgery (CSRF) vulnerability in Oscommerce 2.2
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.
6.0
2008-09-22 CVE-2008-4170 Information Exposure vulnerability in Oscommerce 2.2
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
network
low complexity
oscommerce CWE-200
5.0
2006-12-14 CVE-2006-6534 Input Validation vulnerability in Oscommerce 3.0A3
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selected_box parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languages_definitions.php, or the (4) pID parameter to admin/products.php.
network
oscommerce
4.3
2006-10-10 CVE-2006-5190 Cross-Site Scripting vulnerability in osCommerce
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.
network
oscommerce
4.3
2006-08-23 CVE-2006-4298 Directory Traversal vulnerability in Oscommerce 2.2Ms220060817
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence of arbitrary files and disclose the installation path via a ..
network
low complexity
oscommerce
5.0
2005-06-16 CVE-2005-1951 HTTP Response Splitting vulnerability in osCommerce
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.
network
low complexity
oscommerce
5.0
2005-05-02 CVE-2005-0458 Cross-Site Scripting vulnerability in Oscommerce 2.2Ms2
Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.
network
oscommerce
4.3