Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) bannermanager.php, (b) bannerstatistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) ordersstatus.php, (i) productsattributes.php, (j) productsexpected.php, (k) reviews.php, (l) specials.php, (m) statsproductspurchased.php, (n) statsproductsviewed.php, (o) taxclasses.php, (p) taxrates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geozones.php.
Directory traversal vulnerability in filemanager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) productsid or (2) pid parameter to index.php or (3) goto parameter to banner.php.