CVE Database
/

CVE-2005-4677

Back to search

CVE-2005-4677

Published: Feb 1, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

19874
vdb-entry
x_refsource_OSVDB
17082
third-party-advisory
x_refsource_SECUNIA
15023
vdb-entry
x_refsource_BID
ADV-2005-1974
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now