Show filters
224 Total Results
Displaying 201-210 of 224
Sort by:
Attacker Value
Unknown

CVE-2009-0408

Disclosure Date: February 03, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.
0
Attacker Value
Unknown

CVE-2008-5219

Disclosure Date: November 25, 2008 (last updated October 04, 2023)
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.
0
Attacker Value
Unknown

CVE-2008-4170

Disclosure Date: September 22, 2008 (last updated October 04, 2023)
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2008-1838

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.
0
Attacker Value
Unknown

CVE-2008-1224

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrary web script or HTML via the returnTo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-0719

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.
0
Attacker Value
Unknown

CVE-2007-4959

Disclosure Date: September 18, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-3236

Disclosure Date: June 15, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.
0
Attacker Value
Unknown

CVE-2006-6533

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PHP files via a .. (dot dot) in the filter parameter. NOTE: this issue can be leveraged to obtain full path information in error messages.
0
Attacker Value
Unknown

CVE-2006-6534

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selected_box parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languages_definitions.php, or the (4) pID parameter to admin/products.php.
0