CVE-2012-1664

oscmax < 2.5.0 - Cross-Site Scripting in Admin Panel

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 9 public exploits for CVE-2012-1664. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in osCMax 2.5.0, with an example XSS payload. It lacks executable exploit code but outlines attack vectors.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process action to admin/login.php; (2) pageTitle, (3) current_product_id, or (4) cPath parameter to admin/new_attributes_include.php; (5) sb_id, (6) sb_key, (7) gc_id, (8) gc_key, or (9) path parameter to admin/htaccess.php; (10) title parameter to admin/information_form.php; (11) search parameter to admin/xsell.php; (12) gross or (13) max parameter to admin/stats_products_purchased.php; (14) status parameter to admin/stats_monthly_sales.php; (15) sorted parameter to admin/stats_customers.php; (16) information_id parameter to /admin/information_manager.php; or (17) zID parameter to /admin/geo_zones.php.

Exploits (9)

exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37040

The provided text describes SQL injection and XSS vulnerabilities in osCMax 2.5.0, with an example XSS payload. It lacks executable exploit code but outlines attack vectors.

Classification
Writeup 90%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Theoretical
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37041

The provided text describes multiple SQL injection and XSS vulnerabilities in osCMax 2.5.0, with example URLs demonstrating XSS payloads. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the vulnerable admin endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37042

The provided text describes a cross-site scripting (XSS) vulnerability in osCMax 2.5.0, where unsanitized user input in the 'status' parameter of 'stats_monthly_sales.php' allows execution of arbitrary JavaScript code. The example demonstrates a basic XSS payload to steal cookies.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the vulnerable admin page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37043

The provided text describes a vulnerability in osCMax 2.5.0, specifically SQL injection and XSS vulnerabilities due to insufficient input sanitization. It includes an example XSS payload but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the target URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37046

The provided text describes a cross-site scripting (XSS) vulnerability in osCMax 2.5.0, where user-supplied input is not sufficiently sanitized. The example demonstrates an XSS payload injected via the 'pageTitle' parameter in the admin interface.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
Auth required
Prerequisites: Access to the admin interface · User interaction or reflected XSS context
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37038

This exploit demonstrates a cross-site scripting (XSS) vulnerability in osCMax 2.5.0 by injecting a malicious script into the username field of a login form. The script executes when processed, potentially stealing cookie-based authentication credentials.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the target login page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37044

The provided text describes a cross-site scripting (XSS) vulnerability in osCMax 2.5.0, where user-supplied input is not sufficiently sanitized. The example URL demonstrates an XSS payload that could steal cookie-based authentication credentials.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the vulnerable URL endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37039

This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in osCMax 2.5.0 by injecting malicious scripts into form fields. The PoC shows how unsanitized input can lead to arbitrary JavaScript execution in the context of the admin panel.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the target admin panel URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37045

The provided text describes a cross-site scripting (XSS) vulnerability in osCMax 2.5.0, where unsanitized user input in the 'zID' parameter allows execution of arbitrary JavaScript. The example demonstrates a basic XSS payload to steal cookies.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.5.0
No auth needed
Prerequisites: Access to the vulnerable admin page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80906
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80912
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80905
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80908
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80910
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80911
Various Sources x_refsource_confirm
http://bugtrack.oscmax.com/view.php?id=1165
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80904
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80909
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80907
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/80903

Scores

EPSS 0.0286
EPSS Percentile 84.9%

Details

CWE
CWE-79
Status published
Products (1)
oscmax/oscmax < 2.5.0
Published May 20, 2015
Tracked Since Feb 18, 2026