CVE-2005-4677

SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oscommerce:oscommerce:1.1:*:*:*:*:*:*:*
cpe:2.3:a:oscommerce:oscommerce:1.11:*:*:*:*:*:*:*
cpe:2.3:a:oscommerce:oscommerce:1.12:*:*:*:*:*:*:*
cpe:2.3:a:oscommerce:oscommerce:1.13:*:*:*:*:*:*:*

History

07 Nov 2023, 01:58

Type Values Removed Values Added
References
  • {'url': 'http://www.oscommerce.com/community/contributions,1032', 'name': 'http://www.oscommerce.com/community/contributions,1032', 'tags': [], 'refsource': 'MISC'}
  • () http://www.oscommerce.com/community/contributions%2C1032 -

Information

Published : 2005-12-31 05:00

Updated : 2023-12-10 10:28


NVD link : CVE-2005-4677

Mitre link : CVE-2005-4677

CVE.ORG link : CVE-2005-4677


JSON object : View

Products Affected

oscommerce

  • oscommerce