Multiple SQL injection vulnerabilities in the admin panel in osCMax...
Vulnerability Description
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-1665
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.htbridge.com/advisory/HTB23081
- http://www.osvdb.org/80901
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html
- http://bugtrack.oscmax.com/view.php?id=1165
- http://www.osvdb.org/80902
- http://www.osvdb.org/80900
- http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update
Affected Vendor
oscmax
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.