Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Poll Booth HIGH 7.5
CVE-2008-4765

SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the po…

No fix yet
Fix from $1,950 2008-10-28
Oscommerce MEDIUM 5.0
CVE-2008-4170

create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the in…

Mitigation only
Fix from $1,600 2008-09-22
Customer Testimonials HIGH 7.5
CVE-2008-0719

SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remot…

No fix yet
Fix from $1,950 2008-02-12
Php Point Of Sale HIGH 7.5
CVE-2007-1477

Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local…

Mitigation only
Fix from $1,950 2007-03-16
Oscommerce HIGH 7.5
CVE-2006-6533

Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PH…

No fix yet
Fix from $1,950 2006-12-14
Oscommerce HIGH 7.5
CVE-2006-4297

SQL injection vulnerability in shopping_cart.php in osCommerce before 2.2 Milestone 2 060817 allows remote attackers to execute arbitrary SQL command…

Patch available
Fix from $1,950 2006-08-23
Oscommerce MEDIUM 5.0
CVE-2006-4298

Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence o…

No fix yet
Fix from $1,600 2006-08-23
Oscommerce MEDIUM 5.0
CVE-2005-2330EPSS 10%

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) …

No fix yet
Fix from $1,600 2005-07-20
Oscommerce MEDIUM 5.0
CVE-2005-1951

Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web…

Mitigation only
Fix from $1,600 2005-06-16
Oscommerce HIGH 7.5
CVE-2004-2638

The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login p…

Patch available
Fix from $1,950 2004-12-31
Oscommerce MEDIUM 5.0
CVE-2004-2021

Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the fil…

No fix yet
Fix from $1,600 2004-12-31
Oscommerce HIGH 7.5
CVE-2002-1991EPSS 7%

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

No fix yet
Fix from $1,950 2002-12-31
Oscommerce HIGH 7.5
CVE-2002-2019

PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2002-12-31