Description
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
Remediation
References
Related Vulnerabilities
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-13662)
Joomla Improper Input Validation Vulnerability (CVE-2015-8565)
WordPress Plugin Social Auto Poster-WordPress Scheduler & Marketing Arbitrary File Upload (5.3.14)
WordPress Plugin We�re Open! Cross-Site Scripting (1.41)
Oracle Database Server CVE-2009-1020 Vulnerability (CVE-2009-1020)