Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2023-43712
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "acc…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43713
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability,
which allows attackers to inject JS via the "title" parameter, in…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43707
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "Cat…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43708
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "con…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43709
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "con…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43710
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "con…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43711
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "adm…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43702
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tra…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43703
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "pro…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43704
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tit…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43705
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "tra…
Oscommerce
No fix yet
MEDIUM 5.4
CVE-2023-43706
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability allows attackers to inject JS through the "ema…
Oscommerce
No fix yet
CRITICAL 9.8
CVE-2020-23360
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /c…
Oscommerce
No fix yet
HIGH 7.2
CVE-2018-18573
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.…
Oscommerce
Mitigation only
HIGH 7.2
CVE-2018-18572
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP…
Oscommerce
Mitigation only
MEDIUM 5.8
CVE-2012-5792
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…
Oscommerce
No fix yet
MEDIUM 5.8
CVE-2012-5796
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…
Oscommerce
No fix yet
MEDIUM 5.8
CVE-2012-5798
The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or su…
Oscommerce
No fix yet
HIGH 7.5
CVE-2011-4543
Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .. (dot do…
Oscommerce
No fix yet
MEDIUM 5.0
CVE-2011-3767
osCommerce 3.0a5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …
Oscommerce
Mitigation only
MEDIUM 6.0
CVE-2009-0408
Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.
Oscommerce
Mitigation only
HIGH 7.5
CVE-2008-4765
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the po…
Poll Booth
No fix yet
MEDIUM 5.0
CVE-2008-4170
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the in…
Oscommerce
Mitigation only
HIGH 7.5
CVE-2008-0719
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remot…
Customer Testimonials
No fix yet
HIGH 7.5
CVE-2007-1477
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local…
Php Point Of Sale
Mitigation only
HIGH 7.5
CVE-2006-6533
Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PH…
Oscommerce
No fix yet
MEDIUM 5.0
CVE-2006-4298
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence o…
Oscommerce
No fix yet
MEDIUM 5.0
CVE-2005-2330EPSS 10%
Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) …
Oscommerce
No fix yet
MEDIUM 5.0
CVE-2005-1951
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web…
Oscommerce
Mitigation only
MEDIUM 5.0
CVE-2004-2021
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the fil…
Oscommerce
No fix yet