Description
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/18455
References (6)
Core 6
Core References
Exploit x_refsource_misc
http://packetstormsecurity.org/files/109389/VL-407.txt
Various Sources x_refsource_misc
http://www.vulnerability-lab.com/get_content.php?id=407
Patch x_refsource_confirm
https://github.com/osCommerce/oscommerce/commit/a5aeb0448cc333cc4b801c0e01981b218fd9c7df
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72916
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51831
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/18455
Scores
EPSS
0.0701
EPSS Percentile
91.6%
Details
CWE
CWE-79
Status
published
Products (1)
oscommerce/online_merchant
3.0.2
Published
Feb 14, 2012
Tracked Since
Feb 18, 2026