osCommerce 2.2 - 'product_info.php' Denial of Service

EDB-ID:

22494

CVE:





Platform:

PHP

Date:

2003-04-15


source: https://www.securityfocus.com/bid/7351/info

It has been reported that an attacker may trigger a denial of service condition in osCommerce application. If malicious URI parameters are passed to several of the osCommerce PHP pages, the mySQL and web server hosting osCommerce reportedly becomes unstable, possibly resulting in a denial of service condition.

It should be noted that although osCommerce version 2.2cvs was reported vulnerable, previous versions may also be affected. 

product_info.php?products_id=[large amount of random content]