Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oscommerce oscommerce vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-5795
The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary val...
Akunamachata Paypal Express Module -
Oscommerce Oscommerce -
NA
CVE-2006-4298
Multiple directory traversal vulnerabilities in cache.php in osCommerce prior to 2.2 Milestone 2 060817 allow remote malicious users to determine existence of arbitrary files and disclose the installation path via a .. (dot dot) in unspecified parameters in the (1) tep_cache_also...
Oscommerce Oscommerce 2.2 Ms2 2006-08-17
NA
CVE-2006-4297
SQL injection vulnerability in shopping_cart.php in osCommerce prior to 2.2 Milestone 2 060817 allows remote malicious users to execute arbitrary SQL commands via id array parameters.
Oscommerce Oscommerce 2.2 Ms2 2006-08-17
NA
CVE-2012-5792
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary va...
Oscommerce Oscommerce -
Sagepay Sage Pay Direct Module -
NA
CVE-2012-5793
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary vali...
Oscommerce Oscommerce -
Harald Ponce De Leon Authorize.net -
NA
CVE-2012-5798
The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitr...
Paypal Payflow Pro Express Checkout -
Oscommerce Oscommerce -
NA
CVE-2012-5797
The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary...
Brian Burton Paypal Pro Payflow Module -
Oscommerce Oscommerce -
NA
CVE-2014-10033
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and previous versions allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.
Oscommerce Online Merchant
1 EDB exploit
NA
CVE-2009-2039
Unspecified vulnerability in the Luottokunta module prior to 1.3 for osCommerce has unknown impact and attack vectors related to orders.
Oscommerce Luottokunta 1.3
6.1
CVSSv3
CVE-2020-12058
Several XSS vulnerabilities in osCommerce CE Phoenix prior to 1.0.6.0 allow an malicious user to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog...
Oscommerce Ce Phoenix 1.0.6.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »