Show filters
224 Total Results
Displaying 181-190 of 224
Sort by:
Attacker Value
Unknown

CVE-2012-5794

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-5796

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-5792

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-5163

Disclosure Date: September 26, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an enable_category action to index.php.
0
Attacker Value
Unknown

CVE-2012-5162

Disclosure Date: September 26, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) edit_category_post or (2) enable_category action to index.php.
0
Attacker Value
Unknown

CVE-2012-1617

Disclosure Date: September 26, 2012 (last updated October 05, 2023)
Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.
0
Attacker Value
Unknown

CVE-2012-0973

Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2012-0974

Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.
0
Attacker Value
Unknown

CVE-2012-4282

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2012-0312

Disclosure Date: January 26, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0