Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oscommerce oscommerce - vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-6609
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %27%22%3E%3Cimg%2Fsrc%3D1+onerror%3Dalert%28document.cookie%2...
Oscommerce Oscommerce 4.0
5
CVSSv2
CVE-2008-4170
create_account.php in osCommerce 2.2 RC 2a allows remote malicious users to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
Oscommerce Oscommerce 2.2
7.5
CVSSv2
CVE-2020-23360
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
Oscommerce Oscommerce 2.3.4.1
6
CVSSv2
CVE-2009-0408
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote malicious users to hijack the authentication of administrators.
Oscommerce Oscommerce 2.2
7.5
CVSSv2
CVE-2004-2638
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote malicious users to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.
Oscommerce Oscommerce 1.5.1
7.5
CVSSv2
CVE-2002-1991
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
Oscommerce Oscommerce 2.1
1 EDB exploit
7.5
CVSSv2
CVE-2002-2019
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote malicious users to execute arbitrary PHP code via the include_file parameter.
Oscommerce Oscommerce 2.1
1 EDB exploit
5.8
CVSSv2
CVE-2012-5794
The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid...
Moneybookers Moneybookers -
Oscommerce Oscommerce -
7.5
CVSSv2
CVE-2006-4297
SQL injection vulnerability in shopping_cart.php in osCommerce prior to 2.2 Milestone 2 060817 allows remote malicious users to execute arbitrary SQL commands via id array parameters.
Oscommerce Oscommerce 2.2 Ms2 2006-08-17
5
CVSSv2
CVE-2006-4298
Multiple directory traversal vulnerabilities in cache.php in osCommerce prior to 2.2 Milestone 2 060817 allow remote malicious users to determine existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1) tep_cache_also...
Oscommerce Oscommerce 2.2 Ms2 2006-08-17
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »