CVE-2006-6534: XSS
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selectedbox parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languagesdefinitions.php, or the (4) pID parameter to admin/products.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6534?
CVE-2006-6534 is considered a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
How do I fix CVE-2006-6534?
To fix CVE-2006-6534, update to a secure version of osCommerce that addresses these XSS vulnerabilities.
What types of systems are affected by CVE-2006-6534?
CVE-2006-6534 specifically affects osCommerce version 3.0a3.
Can CVE-2006-6534 be exploited without user interaction?
Yes, CVE-2006-6534 can be exploited by attackers without requiring user interaction, making it particularly dangerous.
What are the common attack vectors for CVE-2006-6534?
Common attack vectors for CVE-2006-6534 include injecting malicious scripts through vulnerable parameters in the osCommerce platform.