CVE-2012-1665

Oscmax < 2.5.0 - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/37048
exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · htmlwebappsphp
https://www.exploit-db.com/exploits/37047

Scores

EPSS 0.0186
EPSS Percentile 83.1%

Details

CWE
CWE-89
Status published
Products (1)
oscmax/oscmax < 2.5.0
Published May 20, 2015
Tracked Since Feb 18, 2026