CVE

Id
15881  
CVE No.
CVE-2005-4677  
Status
Candidate  
Description
SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.  
Phase
Assigned (20060131)  
Votes
None (candidate not yet proposed)  
Comments