PHP remote file inclusion vulnerability in includeonce.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the includefile parameter.
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the includefile parameter to includeonce.php.
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) bannermanager.php, (b) bannerstatistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) ordersstatus.php, (i) productsattributes.php, (j) productsexpected.php, (k) reviews.php, (l) specials.php, (m) statsproductspurchased.php, (n) statsproductsviewed.php, (o) taxclasses.php, (p) taxrates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geozones.php.
Directory traversal vulnerability in filemanager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) productsid or (2) pid parameter to index.php or (3) goto parameter to banner.php.