CVE-2005-4677

SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oscommerce:oscommerce:1.1:*:*:*:*:*:*:*
cpe:2.3:a:oscommerce:oscommerce:1.11:*:*:*:*:*:*:*
cpe:2.3:a:oscommerce:oscommerce:1.12:*:*:*:*:*:*:*
cpe:2.3:a:oscommerce:oscommerce:1.13:*:*:*:*:*:*:*

History

21 Nov 2024, 00:04

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0124.html - () http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0124.html -
References () http://secunia.com/advisories/17082 - () http://secunia.com/advisories/17082 -
References () http://www.oscommerce.com/community/contributions%2C1032 - () http://www.oscommerce.com/community/contributions%2C1032 -
References () http://www.osvdb.org/19874 - () http://www.osvdb.org/19874 -
References () http://www.securityfocus.com/bid/15023 - () http://www.securityfocus.com/bid/15023 -
References () http://www.vupen.com/english/advisories/2005/1974 - () http://www.vupen.com/english/advisories/2005/1974 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/22528 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/22528 -

07 Nov 2023, 01:58

Type Values Removed Values Added
References
  • {'url': 'http://www.oscommerce.com/community/contributions,1032', 'name': 'http://www.oscommerce.com/community/contributions,1032', 'tags': [], 'refsource': 'MISC'}
  • () http://www.oscommerce.com/community/contributions%2C1032 -

Information

Published : 2005-12-31 05:00

Updated : 2024-11-21 00:04


NVD link : CVE-2005-4677

Mitre link : CVE-2005-4677

CVE.ORG link : CVE-2005-4677


JSON object : View

Products Affected

oscommerce

  • oscommerce