Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Jun 16, 2026
CVE-2005-4677
CVE-2005-4677
Description
SQL injection vulnerability in additional_images.php (aka the Additional Images module) before 1.14 in osCommerce allows remote attackers to execute arbitrary SQL commands via the products_id parameter to product_info.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.14
Patches
Vulnerability mechanics
References
7- archives.neohapsis.com/archives/fulldisclosure/2005-10/0124.htmlnvd
- secunia.com/advisories/17082nvd
- www.oscommerce.com/community/contributions%2C1032nvd
- www.osvdb.org/19874nvd
- www.securityfocus.com/bid/15023nvd
- www.vupen.com/english/advisories/2005/1974nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/22528nvd
News mentions
0No linked articles in our index yet.