osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOscommerce
APPOscommerce< 1.0.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
Related vulnerabilities
CVE-2020-23360CRITICAL9.8PL ✓same product
osCommerce 2.3.4.1 — błąd weryfikacji hasła umożliwia ominięcie kontroli
CVE-2019-25496HIGH8.8same product
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2019-25495HIGH8.8same product
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2019-25497HIGH8.8same product
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2023-6579HIGH7.3same product
A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is s...