Oscommerce

Online Merchant

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.85%
  • Published 23.07.2025 13:50:09
  • Last modified 25.07.2025 15:29:44

A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after in...

  • EPSS 0.22%
  • Published 06.11.2018 04:29:00
  • Last modified 21.11.2024 03:56:57

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg e...

  • EPSS 0.22%
  • Published 06.11.2018 04:29:00
  • Last modified 21.11.2024 03:56:57

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several alternative cases in which HTML can be executed, such as a file with ...

  • EPSS 0.22%
  • Published 06.11.2018 04:29:00
  • Last modified 21.11.2024 03:56:57

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.

Exploit
  • EPSS 0.91%
  • Published 13.01.2015 15:59:42
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.

  • EPSS 0.6%
  • Published 19.09.2012 19:55:05
  • Last modified 11.04.2025 00:51:21

The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the re...

Exploit
  • EPSS 0.23%
  • Published 27.05.2012 19:55:01
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML vi...

  • EPSS 0.23%
  • Published 27.05.2012 19:55:01
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different...

Exploit
  • EPSS 11.25%
  • Published 14.02.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated...

  • EPSS 0.25%
  • Published 26.01.2012 15:55:01
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.