Description
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-0072 Vulnerability (CVE-2012-0072)
MySQL CVE-2017-3650 Vulnerability (CVE-2017-3650)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0299)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2008-1672)
WordPress Plugin BibleGet I/O Unspecified Vulnerability (3.4)