Show filters
378 Total Results
Displaying 301-310 of 378
Sort by:
Attacker Value
Unknown
CVE-2012-5792
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2012-1639
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.
0
Attacker Value
Unknown
CVE-2012-2991
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
0
Attacker Value
Unknown
CVE-2012-2116
Disclosure Date: August 31, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart.
0
Attacker Value
Unknown
CVE-2012-2935
Disclosure Date: May 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different vulnerability than CVE-2012-1059.
0
Attacker Value
Unknown
CVE-2012-1792
Disclosure Date: May 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the name parameter to oscommerce/index.php, which is not properly handled in an error message. NOTE: this might not be a vulnerability, since the ability to access oscommerce/index.php during installation may already imply administrator privileges.
0
Attacker Value
Unknown
CVE-2008-7310
Disclosure Date: April 05, 2012 (last updated October 04, 2023)
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.
0
Attacker Value
Unknown
CVE-2008-7311
Disclosure Date: April 05, 2012 (last updated October 04, 2023)
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.
0
Attacker Value
Unknown
CVE-2012-1059
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.
0
Attacker Value
Unknown
CVE-2012-0312
Disclosure Date: January 26, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0