CPE, qui signifie Common Platform Enumeration, est un système normalisé de dénomination du matériel, des logiciels et des systèmes d'exploitation. CPE fournit un schéma de dénomination structuré pour identifier et classer de manière unique les systèmes informatiques, les plates-formes et les progiciels sur la base de certains attributs tels que le fournisseur, le nom du produit, la version, la mise à jour, l'édition et la langue.
CWE, ou Common Weakness Enumeration, est une liste complète et une catégorisation des faiblesses et des vulnérabilités des logiciels. Elle sert de langage commun pour décrire les faiblesses de sécurité des logiciels au niveau de l'architecture, de la conception, du code ou de la mise en œuvre, qui peuvent entraîner des vulnérabilités.
CAPEC, qui signifie Common Attack Pattern Enumeration and Classification (énumération et classification des schémas d'attaque communs), est une ressource complète, accessible au public, qui documente les schémas d'attaque communs utilisés par les adversaires dans les cyberattaques. Cette base de connaissances vise à comprendre et à articuler les vulnérabilités communes et les méthodes utilisées par les attaquants pour les exploiter.
Services & Prix
Aides & Infos
Recherche de CVE id, CWE id, CAPEC id, vendeur ou mots clés dans les CVE
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Métriques
Métriques
Score
Gravité
CVSS Vecteur
Source
V2
4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
nvd@nist.gov
EPSS
EPSS est un modèle de notation qui prédit la probabilité qu'une vulnérabilité soit exploitée.
Score EPSS
Le modèle EPSS produit un score de probabilité compris entre 0 et 1 (0 et 100 %). Plus la note est élevée, plus la probabilité qu'une vulnérabilité soit exploitée est grande.
Date
EPSS V0
EPSS V1
EPSS V2 (> 2022-02-04)
EPSS V3 (> 2025-03-07)
EPSS V4 (> 2025-03-17)
2022-02-06
–
–
2.61%
–
–
2022-03-20
–
–
2.61%
–
–
2022-04-03
–
–
2.61%
–
–
2022-05-01
–
–
2.95%
–
–
2022-07-17
–
–
2.95%
–
–
2023-02-26
–
–
2.95%
–
–
2023-03-12
–
–
–
0.75%
–
2023-08-06
–
–
–
0.75%
–
2024-02-11
–
–
–
0.75%
–
2024-03-10
–
–
–
0.77%
–
2024-06-02
–
–
–
0.77%
–
2024-08-25
–
–
–
0.77%
–
2024-09-22
–
–
–
0.77%
–
2024-09-29
–
–
–
0.77%
–
2024-12-22
–
–
–
0.67%
–
2025-01-19
–
–
–
0.67%
–
2025-03-18
–
–
–
–
7.86%
2025-04-24
–
–
–
–
7.86%
2025-04-28
–
–
–
–
7.86%
2025-05-01
–
–
–
–
7.86%
2025-05-05
–
–
–
–
7.86%
2025-05-05
–
–
–
–
7.86,%
Percentile EPSS
Le percentile est utilisé pour classer les CVE en fonction de leur score EPSS. Par exemple, une CVE dans le 95e percentile selon son score EPSS est plus susceptible d'être exploitée que 95 % des autres CVE. Ainsi, le percentile sert à comparer le score EPSS d'une CVE par rapport à d'autres CVE.
Date de publication : 2012-02-01 23h00 +00:00 Auteur : Vulnerability-Lab EDB Vérifié : Yes
Title:
======
OSCommerce v3.0.2 - Persistent Cross Site Vulnerability
Date:
=====
2012-02-02
VL-ID:
=====
407
Introduction:
=============
osCommerce is the leading Open Source online shop e-commerce solution that is available for free under the
GNU General Public License. It features a rich set of out-of-the-box online shopping cart functionality that
allows store owners to setup, run, and maintain their online stores with minimum effort and with no costs,
license fees, or limitations involved.
The goal of the osCommerce project is to continually evolve by attracting a community that supports the ongoing
development of the project at its core level and extensively through contributions to provide additional
functionality to the already existing rich feature set.
Everything you need to get started in selling physical and digital goods over the internet, from the Catalog frontend
that is presented to your customers, to the Administration Tool backend that completely handles your products,
customers, orders, and online store data.
(Copy of the Vendor Homepage: http://www.opensourcecms.com/scripts/details.php?scriptid=94&name=osCommerce)
Abstract:
=========
Vulnerability-Lab Team (F0x) discovered a persistent Cross Site Scripting Vulnerability on the OSCommerce Shop Software.
Report-Timeline:
================
2012-02-02: Public or Non-Public Disclosure
Status:
========
Published
Affected Products:
==================
Exploitation-Technique:
=======================
Remote
Severity:
=========
Medium
Details:
========
Multiple persistant cross site vulnerabilities are detected on the OSCommerce v3.0.2.
The bug allows remote attacker to implement malicious script code on the application side.
Successful exploitation of the vulnerability allows an attacker to manipulate specific modules & can
lead to session hijacking (user/mod/admin).
Vulnerable Module(s):
[+]index.php?Cart
Proof of Concept:
=================
The vulnerability can be exploited by local low privileged user account with required medium user inter action. For demonstration or reproduce ...
PoC:
"'><img src=vul onerror=alert('vulnerabilitylab')> in the "front" field of the shirt module.
Output:
Size: Medium<br/>- Front: "'><img src=vul onerror=alert('vulnerabilitylab')>
Risk:
=====
The security risk of the persistent vulnerability is estimated as medium.
Credits:
========
Vulnerability Research Laboratory - Alexander Fuchs (F0x23)
Disclaimer:
===========
The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties,
either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-
Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business
profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some
states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation
may not apply. Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability-
Lab. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of
other media, are reserved by Vulnerability-Lab or its suppliers.
Copyright � 2012|Vulnerability-Lab
--
Website: www.vulnerability-lab.com ; vuln-lab.com or vuln-db.com
Contact: admin@vulnerability-lab.com or support@vulnerability-lab.com