Show filters
75 Total Results
Displaying 41-50 of 75
Sort by:
Attacker Value
Unknown
CVE-2022-35212
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().
0
Attacker Value
Unknown
CVE-2020-23360
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
0
Attacker Value
Unknown
CVE-2020-29070
Disclosure Date: November 25, 2020 (last updated February 22, 2025)
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
0
Attacker Value
Unknown
CVE-2020-27975
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
0
Attacker Value
Unknown
CVE-2020-27976
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
0
Attacker Value
Unknown
CVE-2018-18572
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
0
Attacker Value
Unknown
CVE-2018-18573
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
0
Attacker Value
Unknown
CVE-2015-2965
Disclosure Date: June 28, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in osCommerce Japanese 2.2ms1j-R8 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5795
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2012-5797
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0