Vulnerability index

Browse CVEs

62 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Oscommerce MEDIUM 5.4
CVE-2023-43712

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "acc…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43713

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43707

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "Cat…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43708

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43709

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43710

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "con…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43711

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "adm…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43702

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tra…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43703

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "pro…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43704

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tit…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43705

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tra…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce MEDIUM 5.4
CVE-2023-43706

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ema…

No fix yet
Fix from $1,600 2023-09-30
Oscommerce CRITICAL 9.8
CVE-2020-23360

oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /c…

No fix yet
Fix from $2,300 2021-01-27
Oscommerce HIGH 7.2
CVE-2018-18573

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.…

Mitigation only
Fix from $1,950 2019-08-22
Oscommerce HIGH 7.2
CVE-2018-18572

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP…

Mitigation only
Fix from $1,950 2019-08-22
Oscommerce MEDIUM 5.8
CVE-2012-5792

The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5796

The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5798

The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or su…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce HIGH 7.5
CVE-2011-4543

Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .. (dot do…

No fix yet
Fix from $1,950 2011-12-05
Oscommerce MEDIUM 5.0
CVE-2011-3767

osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

Mitigation only
Fix from $1,600 2011-09-24
Oscommerce MEDIUM 6.0
CVE-2009-0408

Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.

Mitigation only
Fix from $1,600 2009-02-03
Poll Booth HIGH 7.5
CVE-2008-4765

SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the po…

No fix yet
Fix from $1,950 2008-10-28
Oscommerce MEDIUM 5.0
CVE-2008-4170

create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the in…

Mitigation only
Fix from $1,600 2008-09-22
Customer Testimonials HIGH 7.5
CVE-2008-0719

SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remot…

No fix yet
Fix from $1,950 2008-02-12
Php Point Of Sale HIGH 7.5
CVE-2007-1477

Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local…

Mitigation only
Fix from $1,950 2007-03-16
Oscommerce HIGH 7.5
CVE-2006-6533

Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PH…

No fix yet
Fix from $1,950 2006-12-14
Oscommerce MEDIUM 5.0
CVE-2006-4298

Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence o…

No fix yet
Fix from $1,600 2006-08-23
Oscommerce MEDIUM 5.0
CVE-2005-2330EPSS 10%

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) …

No fix yet
Fix from $1,600 2005-07-20
Oscommerce MEDIUM 5.0
CVE-2005-1951

Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web…

Mitigation only
Fix from $1,600 2005-06-16
Oscommerce MEDIUM 5.0
CVE-2004-2021

Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the fil…

No fix yet
Fix from $1,600 2004-12-31