Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oscommerce oscommerce vulnerabilities and exploits
(subscribe to this query)
891
VMScore
CVE-2020-27976
osCommerce Phoenix CE prior to 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
Oscommerce Oscommerce
890
VMScore
CVE-2009-2039
Unspecified vulnerability in the Luottokunta module prior to 1.3 for osCommerce has unknown impact and attack vectors related to orders.
Oscommerce Luottokunta 1.3
890
VMScore
CVE-2009-2038
Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges.
Oscommerce Finnish Bank Payment
760
VMScore
CVE-2008-4765
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote malicious users to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
Oscommerce Poll Booth 2.0
2 EDB exploits
755
VMScore
CVE-2010-4946
SQL injection vulnerability in product_info.php in ALLPC 2.5 allows remote malicious users to execute arbitrary SQL commands via the products_id parameter.
Allpcscript Allpc 2.5
1 EDB exploit
755
VMScore
CVE-2008-0719
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote malicious users to execute arbitrary SQL commands via the testimonial_id parameter.
Oscommerce Customer Testimonials 3.1
Oscommerce Oscommerce 2.2
1 EDB exploit
755
VMScore
CVE-2006-0478
CRE Loaded 6.15 allows remote malicious users to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch...
Cre Loaded Cre Loaded 6.15
1 EDB exploit
755
VMScore
CVE-2004-2044
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote mali...
Francisco Burzi Php-nuke 5.3.1
Francisco Burzi Php-nuke 5.4
Francisco Burzi Php-nuke 6.5 Rc2
Francisco Burzi Php-nuke 6.5 Rc3
Francisco Burzi Php-nuke 7.2
Francisco Burzi Php-nuke 7.3
Francisco Burzi Php-nuke 5.0
Francisco Burzi Php-nuke 5.5
Francisco Burzi Php-nuke 5.6
Francisco Burzi Php-nuke 6.6
Francisco Burzi Php-nuke 6.7
Oscommerce Osc2nuke 7x 1.0
Paul Laudanski Betanc Php-nuke Bundle
Francisco Burzi Php-nuke 5.0.1
Francisco Burzi Php-nuke 5.1
Francisco Burzi Php-nuke 6.0
Francisco Burzi Php-nuke 6.5
Francisco Burzi Php-nuke 6.9
Francisco Burzi Php-nuke 7.0
Francisco Burzi Php-nuke 5.2
Francisco Burzi Php-nuke 5.2a
Francisco Burzi Php-nuke 6.5 Beta1
1 EDB exploit
755
VMScore
CVE-2002-1991
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
Oscommerce Oscommerce 2.1
1 EDB exploit
755
VMScore
CVE-2002-2019
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote malicious users to execute arbitrary PHP code via the include_file parameter.
Oscommerce Oscommerce 2.1
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-3611
CVE-2024-4947
CVE-2024-32988
CVE-2020-35165
local file inclusion
CVE-2024-4980
bypass
malicious code
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »