First published: Thu Jan 26 2012(Updated: )
Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
osCommerce PHP Point of Sale | <=2.3.0 | |
osCommerce PHP Point of Sale | =2.2 | |
osCommerce Poll Booth | =2.2ms1j-r1 | |
osCommerce Poll Booth | =2.2ms1j-r2 | |
osCommerce Poll Booth | =2.2ms1j-r3 | |
osCommerce Poll Booth | =2.2ms1j-r4 | |
osCommerce Poll Booth | =2.2ms1j-r5 | |
osCommerce Poll Booth | =2.2ms1j-r6a | |
osCommerce Poll Booth | =2.2ms1j-r7 | |
osCommerce Poll Booth | =2.2ms1j-r8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0312 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2012-0312, upgrade to osCommerce 2.3.1 or later.
CVE-2012-0312 affects osCommerce 2.2 before R9 and osCommerce Online Merchant before 2.3.1.
CVE-2012-0312 is a cross-site scripting (XSS) vulnerability.
Yes, remote attackers can exploit CVE-2012-0312 to inject arbitrary web scripts or HTML.