TROYANOSYVIRUS
Volver a CVEs

CVE-2012-1664

N/A

Descripcion

Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process action to admin/login.php; (2) pageTitle, (3) current_product_id, or (4) cPath parameter to admin/new_attributes_include.php; (5) sb_id, (6) sb_key, (7) gc_id, (8) gc_key, or (9) path parameter to admin/htaccess.php; (10) title parameter to admin/information_form.php; (11) search parameter to admin/xsell.php; (12) gross or (13) max parameter to admin/stats_products_purchased.php; (14) status parameter to admin/stats_monthly_sales.php; (15) sorted parameter to admin/stats_customers.php; (16) information_id parameter to /admin/information_manager.php; or (17) zID parameter to /admin/geo_zones.php.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado5/20/2015
Ultima modificacion4/12/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

oscmax:oscmax

Debilidades (CWE)

CWE-79

Referencias

http://bugtrack.oscmax.com/view.php?id=1165(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80903(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80904(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80905(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80906(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80907(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80908(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80909(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80910(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80911(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/80912(af854a3a-2127-422b-91ae-364da2661108)
https://www.htbridge.com/advisory/HTB23081(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.