A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. Defenders responsible for osCommerce osCommerce2 installations, particularly those [truncated]
A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1, affecting the function include of the file includes/classes/payment.php of the component Payment Page. Manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. Defenders responsible for osCommerce osCommerce2 installations, especially those with publicly accessible payment pag [truncated]