Oscommerce

Oscommerce

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.08%
  • Veröffentlicht 27.02.2026 17:23:38
  • Zuletzt bearbeitet 04.03.2026 02:09:46

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shopping_cart.php with malicious c...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 27.02.2026 17:23:37
  • Zuletzt bearbeitet 04.03.2026 02:14:12

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php req...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 27.02.2026 17:23:36
  • Zuletzt bearbeitet 04.03.2026 02:14:42

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the reviews_id parameter. Attackers can send GET requests to product_reviews_write.php with m...

Exploit
  • EPSS 73.85%
  • Veröffentlicht 16.09.2025 14:33:40
  • Zuletzt bearbeitet 17.09.2025 14:18:55

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauth...

  • EPSS 0.09%
  • Veröffentlicht 17.06.2025 08:50:17
  • Zuletzt bearbeitet 17.06.2025 20:50:23

Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerab...

  • EPSS 15.78%
  • Veröffentlicht 30.04.2024 22:15:07
  • Zuletzt bearbeitet 21.11.2024 09:42:40

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attac...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 21.03.2024 04:15:09
  • Zuletzt bearbeitet 27.06.2025 15:21:43

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

  • EPSS 0.04%
  • Veröffentlicht 08.12.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 08:44:11

A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %27%22%3E%3Cimg%2Fsrc%3D1+onerr...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 07.12.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:44:08

A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argume...

  • EPSS 0.11%
  • Veröffentlicht 26.11.2023 22:15:06
  • Zuletzt bearbeitet 21.11.2024 08:43:33

A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the...