Skip to content
Noroxi

osCommerce records

95 published records for vendor oscommerce.

All records

95 records
  • osCommerce POST Parameter shopping-cart sql injection

    CriticalCVSS 9.8No exploitEPSS 24%

    oscommerce · oscommerceDec 7, 2023

  • osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely.

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    oscommerce · oscommerceOct 28, 2020

  • Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.

    CriticalCVSS 10.0No exploitEPSS 2%

    oscommerce · oscommerceJun 12, 2009

  • Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charge

    CriticalCVSS 10.0No exploitEPSS 1%

    oscommerce · oscommerceJun 12, 2009

  • oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the che

    CriticalCVSS 9.8No exploitEPSS 1%

    oscommerce · oscommerceJan 27, 2021

  • osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    oscommerce · oscommerceOct 28, 2020

  • osCommerce 2.3.4.1 SQL Injection via currency Parameter

    HighCVSS 8.8No exploitEPSS 0%

    oscommerce · oscommerceFeb 27, 2026

  • osCommerce 2.3.4.1 SQL Injection via products_id Parameter

    HighCVSS 8.8No exploitEPSS 0%

    oscommerce · oscommerceFeb 27, 2026

  • osCommerce 2.3.4.1 SQL Injection via reviews_id Parameter

    HighCVSS 8.8No exploitEPSS 0%

    oscommerce · oscommerceFeb 27, 2026

  • CVE-2004-2044
    33Monitor

    PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke

    HighCVSS 7.5Proof of conceptEPSS 11%

    francisco burzi · php-nukeJun 1, 2004

  • CVE-2002-1991
    32Monitor

    PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

    HighCVSS 7.5Proof of conceptEPSS 7%

    oscommerce · oscommerceDec 31, 2002

  • CVE-2008-0719
    31Monitor

    SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 all

    HighCVSS 7.5Proof of conceptEPSS 3%

    oscommerce · customer testimonialsFeb 11, 2008

  • CVE-2002-2019
    31Monitor

    PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a.

    HighCVSS 7.5Proof of conceptEPSS 3%

    oscommerce · oscommerceDec 31, 2002

  • CVE-2011-4543
    31Monitor

    Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .

    HighCVSS 7.5No exploitEPSS 3%

    oscommerce · oscommerceDec 5, 2011

  • CVE-2006-6533
    31Monitor

    Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arb

    HighCVSS 7.5No exploitEPSS 2%

    oscommerce · oscommerceDec 13, 2006

  • CVE-2004-2638
    30Monitor

    The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the i

    HighCVSS 7.5No exploitEPSS 2%

    oscommerce · oscommerceDec 31, 2004

  • CVE-2006-4297
    30Monitor

    SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQ

    HighCVSS 7.5No exploitEPSS 1%

    oscommerce · oscommerceAug 22, 2006

  • CVE-2007-1477
    30Monitor

    Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitr

    HighCVSS 7.5No exploitEPSS 1%

    oscommerce · php point of saleMar 16, 2007

  • CVE-2005-4677
    30Monitor

    SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to

    HighCVSS 7.5No exploitEPSS 1%

    oscommerce · oscommerceDec 31, 2005

  • CVE-2008-4765
    30Monitor

    SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands v

    HighCVSS 7.5Proof of conceptEPSS 1%

    oscommerce · poll boothOct 27, 2008

  • osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.

    HighCVSS 7.2No exploitEPSS 3%

    oscommerce · oscommerceAug 22, 2019

  • osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.

    HighCVSS 7.2No exploitEPSS 3%

    oscommerce · oscommerceAug 22, 2019

  • SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier all

    MediumCVSS 6.5Proof of conceptEPSS 2%

    oscommerce · online merchantJan 13, 2015

  • An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administr

    MediumCVSS 6.6No exploitEPSS 0%

    oscommerce · oscommerceMar 21, 2024

  • Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code.

    MediumCVSS 6.1No exploitEPSS 1%

    oscommerce · ce phoenixSep 3, 2020