SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Oscommerce | Oscommerce | 1.1 (including) | 1.1 (including) |
| Oscommerce | Oscommerce | 1.11 (including) | 1.11 (including) |
| Oscommerce | Oscommerce | 1.12 (including) | 1.12 (including) |
| Oscommerce | Oscommerce | 1.13 (including) | 1.13 (including) |