|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
osCommerce contains a flaw that may allow an attacker to add non-existing products into the shopping cart which may prevent customers from removing the products from their cart. No further details have been provided.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Unknown
OSVDB:
Concern
|
|
Solution |
Upgrade to version 2.2-MS3-CVS or higher after the correction date, as it has been reported to fix this vulnerability. Please be advised that the vendor has not incremented the version number to reflect this change, but simply made a change to a file in its Concurrent Version System (CVS). An upgrade is required as there are no known workarounds.
|
|
Products |
|
osCommerce
 |
2.2-MS3-CVS |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|