{"api_version":"1","generated_at":"2026-07-23T07:40:20+00:00","cve":"CVE-2012-6691","urls":{"html":"https://cve.report/CVE-2012-6691","api":"https://cve.report/api/cve/CVE-2012-6691.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-6691","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-6691"},"summary":{"title":"CVE-2012-6691","description":"Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-05-20 18:59:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.htbridge.com/advisory/HTB23081","name":"https://www.htbridge.com/advisory/HTB23081","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html","name":"http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update","name":"http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"osCmax v2.5.1 has been released - Security update! | osCMax - osCommerce Maximized","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/74753","name":"http://www.securityfocus.com/bid/74753","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"osCmax CVE-2012-6691 Multiple Cross Site Request Forgery Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-6691","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6691","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"6691","vulnerable":"1","versionEndIncluding":"2.5.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oscmax","cpe5":"oscmax","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:36:02.322Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.htbridge.com/advisory/HTB23081"},{"name":"20120404 Multiple vulnerabilities in osCmax","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html"},{"name":"74753","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/74753"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-04-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-06-02T16:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://www.htbridge.com/advisory/HTB23081"},{"name":"20120404 Multiple vulnerabilities in osCmax","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html"},{"name":"74753","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/74753"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-6691","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.htbridge.com/advisory/HTB23081","refsource":"MISC","url":"https://www.htbridge.com/advisory/HTB23081"},{"name":"20120404 Multiple vulnerabilities in osCmax","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2012-04/0021.html"},{"name":"74753","refsource":"BID","url":"http://www.securityfocus.com/bid/74753"},{"name":"http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update","refsource":"CONFIRM","url":"http://www.oscmax.com/blog/michael_s/oscmax_v251_has_been_released_security_update"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-6691","datePublished":"2015-05-20T18:00:00.000Z","dateReserved":"2015-05-20T00:00:00.000Z","dateUpdated":"2024-08-06T21:36:02.322Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-05-20 18:59:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oscmax:oscmax:*:*:*:*:*:*:*:*","versionEndIncluding":"2.5.0","matchCriteriaId":"059EE7FB-F49C-4457-BE7E-E04903006A89"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"6691","Ordinal":"1","Title":"CVE-2012-6691","CVE":"CVE-2012-6691","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"6691","Ordinal":"1","NoteData":"Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php.","Type":"Description","Title":"CVE-2012-6691"},{"CveYear":"2012","CveId":"6691","Ordinal":"2","NoteData":"2015-05-20","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"6691","Ordinal":"3","NoteData":"2015-06-02","Type":"Other","Title":"Modified"}]}}}