CVE Database
/

CVE-2006-5190

Back to search

CVE-2006-5190

Published: Oct 6, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

28750
exploit
x_refsource_EXPLOIT-DB
29801
vdb-entry
x_refsource_OSVDB
28746
exploit
x_refsource_EXPLOIT-DB
29803
vdb-entry
x_refsource_OSVDB
ADV-2006-3917
vdb-entry
x_refsource_VUPEN
29798
vdb-entry
x_refsource_OSVDB
29808
vdb-entry
x_refsource_OSVDB
29807
vdb-entry
x_refsource_OSVDB
22275
third-party-advisory
x_refsource_SECUNIA
29802
vdb-entry
x_refsource_OSVDB
29795
vdb-entry
x_refsource_OSVDB
28759
exploit
x_refsource_EXPLOIT-DB
28755
exploit
x_refsource_EXPLOIT-DB
28747
exploit
x_refsource_EXPLOIT-DB
28744
exploit
x_refsource_EXPLOIT-DB
1016979
vdb-entry
x_refsource_SECTRACK
29809
vdb-entry
x_refsource_OSVDB
29799
vdb-entry
x_refsource_OSVDB
28757
exploit
x_refsource_EXPLOIT-DB
28748
exploit
x_refsource_EXPLOIT-DB
29810
vdb-entry
x_refsource_OSVDB
29811
vdb-entry
x_refsource_OSVDB
28758
exploit
x_refsource_EXPLOIT-DB
28753
exploit
x_refsource_EXPLOIT-DB
29797
vdb-entry
x_refsource_OSVDB
29806
vdb-entry
x_refsource_OSVDB
28749
exploit
x_refsource_EXPLOIT-DB
29800
vdb-entry
x_refsource_OSVDB
20343
vdb-entry
x_refsource_BID
oscommerce-page-xss(29355)
vdb-entry
x_refsource_XF
29796
vdb-entry
x_refsource_OSVDB
28743
exploit
x_refsource_EXPLOIT-DB
28754
exploit
x_refsource_EXPLOIT-DB
28745
exploit
x_refsource_EXPLOIT-DB
29804
vdb-entry
x_refsource_OSVDB
28756
exploit
x_refsource_EXPLOIT-DB
29805
vdb-entry
x_refsource_OSVDB
28752
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now