CVE-2012-1664
osCMax 2.5 - '/admin/geo_zones.php?zID' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
10Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process action to admin/login.php; (2) pageTitle, (3) current_product_id, or (4) cPath parameter to admin/new_attributes_include.php; (5) sb_id, (6) sb_key, (7) gc_id, (8) gc_key, or (9) path parameter to admin/htaccess.php; (10) title parameter to admin/information_form.php; (11) search parameter to admin/xsell.php; (12) gross or (13) max parameter to admin/stats_products_purchased.php; (14) status parameter to admin/stats_monthly_sales.php; (15) sorted parameter to admin/stats_customers.php; (16) information_id parameter to /admin/information_manager.php; or (17) zID parameter to /admin/geo_zones.php.
Múltiples vulnerabilidades de XSS en el panel de administración en osCMax anterior a 2.5.1 permiten a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través (1) del parámetro username en una acción de procesos en admin/login.php; del parámetro (2) pageTitle, (3) current_product_id, o (4) cPath en admin/new_attributes_include.php; del parámetro (5) sb_id, (6) sb_key, (7) gc_id, (8) gc_key, o (9) path en admin/htaccess.php; (10) del parámetro title en admin/information_form.php; (11) del parámetro search parameter en admin/xsell.php; del parámetro (12) gross o (13) max en admin/stats_products_purchased.php; (14) del parámetro status en admin/stats_monthly_sales.php; (15) del parámetro sorted en admin/stats_customers.php; (16) del parámetro information_id en /admin/information_manager.php; o (17) del parámetro zID en /admin/geo_zones.php.
osCmax version 2.5.0 suffers from cross site scripting and remote SQL injection vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-03-14 CVE Reserved
- 2012-04-04 First Exploit
- 2012-04-05 CVE Published
- 2024-06-13 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (23)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html | Mailing List | |
http://bugtrack.oscmax.com/view.php?id=1165 | X_refsource_confirm | |
http://www.osvdb.org/80903 | Vdb Entry | |
http://www.osvdb.org/80904 | Vdb Entry | |
http://www.osvdb.org/80905 | Vdb Entry | |
http://www.osvdb.org/80906 | Vdb Entry | |
http://www.osvdb.org/80907 | Vdb Entry | |
http://www.osvdb.org/80908 | Vdb Entry | |
http://www.osvdb.org/80909 | Vdb Entry | |
http://www.osvdb.org/80910 | Vdb Entry | |
http://www.osvdb.org/80911 | Vdb Entry | |
http://www.osvdb.org/80912 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/37045 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37039 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37044 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37038 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37046 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37043 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37042 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37041 | 2012-04-04 | |
https://www.exploit-db.com/exploits/37040 | 2012-04-04 | |
https://www.htbridge.com/advisory/HTB23081 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update | 2015-05-21 |
URL | Date | SRC |
---|