osCommerce kayıtları
oscommerce üreticisine ait 95 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')48
- CWE-20 Improper Input Validation7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
95 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2023-6579İstismar yok | osCommerce POST Parameter shopping-cart sql injectionoscommerce · oscommerce · CWE-89 | Kritik9,8 | — | %24,0 | 7 Ara 2023 |
41Planlayın | CVE-2020-27976Kavram kanıtı | osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely.oscommerce · oscommerce · CWE-78 | Kritik9,8 | — | %7,0 | 28 Eki 2020 |
41Planlayın | CVE-2009-2039İstismar yok | Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.oscommerce · oscommerce | Kritik10,0 | — | %1,8 | 12 Haz 2009 |
40Planlayın | CVE-2009-2038İstismar yok | Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank chargeoscommerce · oscommerce | Kritik10,0 | — | %1,4 | 12 Haz 2009 |
39İzleyin | CVE-2020-23360İstismar yok | oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the cheoscommerce · oscommerce · CWE-697 | Kritik9,8 | — | %1,2 | 27 Oca 2021 |
35İzleyin | CVE-2020-27975İstismar yok | osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.oscommerce · oscommerce · CWE-352 | Yüksek8,8 | — | %0,6 | 28 Eki 2020 |
35İzleyin | CVE-2019-25497İstismar yok | osCommerce 2.3.4.1 SQL Injection via currency Parameteroscommerce · oscommerce · CWE-89 | Yüksek8,8 | — | %0,3 | 27 Şub 2026 |
35İzleyin | CVE-2019-25496İstismar yok | osCommerce 2.3.4.1 SQL Injection via products_id Parameteroscommerce · oscommerce · CWE-89 | Yüksek8,8 | — | %0,3 | 27 Şub 2026 |
35İzleyin | CVE-2019-25495İstismar yok | osCommerce 2.3.4.1 SQL Injection via reviews_id Parameteroscommerce · oscommerce · CWE-89 | Yüksek8,8 | — | %0,3 | 27 Şub 2026 |
33İzleyin | CVE-2004-2044Kavram kanıtı | PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke francisco burzi · php-nuke | Yüksek7,5 | — | %11,0 | 1 Haz 2004 |
32İzleyin | CVE-2002-1991Kavram kanıtı | PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.oscommerce · oscommerce · CWE-94 | Yüksek7,5 | — | %7,5 | 31 Ara 2002 |
31İzleyin | CVE-2008-0719Kavram kanıtı | SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 alloscommerce · customer testimonials · CWE-89 | Yüksek7,5 | — | %2,9 | 11 Şub 2008 |
31İzleyin | CVE-2002-2019Kavram kanıtı | PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a.oscommerce · oscommerce · CWE-94 | Yüksek7,5 | — | %2,6 | 31 Ara 2002 |
31İzleyin | CVE-2011-4543İstismar yok | Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .oscommerce · oscommerce · CWE-22 | Yüksek7,5 | — | %2,6 | 5 Ara 2011 |
31İzleyin | CVE-2006-6533İstismar yok | Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arboscommerce · oscommerce | Yüksek7,5 | — | %1,7 | 13 Ara 2006 |
30İzleyin | CVE-2004-2638İstismar yok | The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the ioscommerce · oscommerce | Yüksek7,5 | — | %1,5 | 31 Ara 2004 |
30İzleyin | CVE-2006-4297İstismar yok | SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQoscommerce · oscommerce | Yüksek7,5 | — | %1,5 | 22 Ağu 2006 |
30İzleyin | CVE-2007-1477İstismar yok | Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitroscommerce · php point of sale | Yüksek7,5 | — | %1,5 | 16 Mar 2007 |
30İzleyin | CVE-2005-4677İstismar yok | SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers tooscommerce · oscommerce | Yüksek7,5 | — | %1,4 | 31 Ara 2005 |
30İzleyin | CVE-2008-4765Kavram kanıtı | SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands voscommerce · poll booth · CWE-89 | Yüksek7,5 | — | %1,0 | 27 Eki 2008 |
29İzleyin | CVE-2018-18573İstismar yok | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.oscommerce · oscommerce · CWE-94 | Yüksek7,2 | — | %2,6 | 22 Ağu 2019 |
29İzleyin | CVE-2018-18572İstismar yok | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.oscommerce · oscommerce · CWE-434 | Yüksek7,2 | — | %2,5 | 22 Ağu 2019 |
27İzleyin | CVE-2014-10033Kavram kanıtı | SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier alloscommerce · online merchant · CWE-89 | Orta6,5 | — | %1,8 | 13 Oca 2015 |
26İzleyin | CVE-2024-22724İstismar yok | An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administroscommerce · oscommerce · CWE-94 | Orta6,6 | — | %0,3 | 21 Mar 2024 |
24İzleyin | CVE-2020-12058İstismar yok | Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code.oscommerce · ce phoenix · CWE-79 | Orta6,1 | — | %1,0 | 3 Eyl 2020 |
- CVE-2023-657946Planlayın
osCommerce POST Parameter shopping-cart sql injection
KritikCVSS 9,8İstismar yokEPSS %24oscommerce · oscommerce7 Ara 2023
- CVE-2020-2797641Planlayın
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely.
KritikCVSS 9,8Kavram kanıtıEPSS %7oscommerce · oscommerce28 Eki 2020
- CVE-2009-203941Planlayın
Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.
KritikCVSS 10,0İstismar yokEPSS %2oscommerce · oscommerce12 Haz 2009
- CVE-2009-203840Planlayın
Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charge
KritikCVSS 10,0İstismar yokEPSS %1oscommerce · oscommerce12 Haz 2009
- CVE-2020-2336039İzleyin
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che
KritikCVSS 9,8İstismar yokEPSS %1oscommerce · oscommerce27 Oca 2021
- CVE-2020-2797535İzleyin
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1oscommerce · oscommerce28 Eki 2020
- CVE-2019-2549735İzleyin
osCommerce 2.3.4.1 SQL Injection via currency Parameter
YüksekCVSS 8,8İstismar yokEPSS %0oscommerce · oscommerce27 Şub 2026
- CVE-2019-2549635İzleyin
osCommerce 2.3.4.1 SQL Injection via products_id Parameter
YüksekCVSS 8,8İstismar yokEPSS %0oscommerce · oscommerce27 Şub 2026
- CVE-2019-2549535İzleyin
osCommerce 2.3.4.1 SQL Injection via reviews_id Parameter
YüksekCVSS 8,8İstismar yokEPSS %0oscommerce · oscommerce27 Şub 2026
- CVE-2004-204433İzleyin
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke
YüksekCVSS 7,5Kavram kanıtıEPSS %11francisco burzi · php-nuke1 Haz 2004
- CVE-2002-199132İzleyin
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
YüksekCVSS 7,5Kavram kanıtıEPSS %7oscommerce · oscommerce31 Ara 2002
- CVE-2008-071931İzleyin
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 all
YüksekCVSS 7,5Kavram kanıtıEPSS %3oscommerce · customer testimonials11 Şub 2008
- CVE-2002-201931İzleyin
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a.
YüksekCVSS 7,5Kavram kanıtıEPSS %3oscommerce · oscommerce31 Ara 2002
- CVE-2011-454331İzleyin
Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .
YüksekCVSS 7,5İstismar yokEPSS %3oscommerce · oscommerce5 Ara 2011
- CVE-2006-653331İzleyin
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arb
YüksekCVSS 7,5İstismar yokEPSS %2oscommerce · oscommerce13 Ara 2006
- CVE-2004-263830İzleyin
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the i
YüksekCVSS 7,5İstismar yokEPSS %2oscommerce · oscommerce31 Ara 2004
- CVE-2006-429730İzleyin
SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQ
YüksekCVSS 7,5İstismar yokEPSS %1oscommerce · oscommerce22 Ağu 2006
- CVE-2007-147730İzleyin
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitr
YüksekCVSS 7,5İstismar yokEPSS %1oscommerce · php point of sale16 Mar 2007
- CVE-2005-467730İzleyin
SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %1oscommerce · oscommerce31 Ara 2005
- CVE-2008-476530İzleyin
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5Kavram kanıtıEPSS %1oscommerce · poll booth27 Eki 2008
- CVE-2018-1857329İzleyin
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
YüksekCVSS 7,2İstismar yokEPSS %3oscommerce · oscommerce22 Ağu 2019
- CVE-2018-1857229İzleyin
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
YüksekCVSS 7,2İstismar yokEPSS %3oscommerce · oscommerce22 Ağu 2019
- CVE-2014-1003327İzleyin
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier all
OrtaCVSS 6,5Kavram kanıtıEPSS %2oscommerce · online merchant13 Oca 2015
- CVE-2024-2272426İzleyin
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administr
OrtaCVSS 6,6İstismar yokEPSS %0oscommerce · oscommerce21 Mar 2024
- CVE-2020-1205824İzleyin
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code.
OrtaCVSS 6,1İstismar yokEPSS %1oscommerce · ce phoenix3 Eyl 2020