CVE-2018-25114
- EPSS 0.85%
- Veröffentlicht 23.07.2025 13:50:09
- Zuletzt bearbeitet 25.07.2025 15:29:44
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after in...
CVE-2018-18964
- EPSS 0.22%
- Veröffentlicht 06.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:57
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg e...
CVE-2018-18965
- EPSS 0.22%
- Veröffentlicht 06.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:57
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several alternative cases in which HTML can be executed, such as a file with ...
CVE-2018-18966
- EPSS 0.22%
- Veröffentlicht 06.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:57
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
CVE-2014-10033
- EPSS 0.91%
- Veröffentlicht 13.01.2015 15:59:42
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.
- EPSS 0.6%
- Veröffentlicht 19.09.2012 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the re...
CVE-2012-1792
- EPSS 0.23%
- Veröffentlicht 27.05.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML vi...
CVE-2012-2935
- EPSS 0.23%
- Veröffentlicht 27.05.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different...
CVE-2012-1059
- EPSS 11.25%
- Veröffentlicht 14.02.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated...
CVE-2012-0312
- EPSS 0.25%
- Veröffentlicht 26.01.2012 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.