CVE-2019-25496 | osCommerce 2.3.4.1 product_info.php products_id sql injection (Exploit 46329 / EDB-46329)
A vulnerability was found in osCommerce 2.3.4.1. It has been rated as critical. This issue affects some unknown processing of the file product_info.php. This manipulation of the argument products_id causes sql injection.
This vulnerability is tracked as CVE-2019-25496. The attack is possible to be carried out remotely. Moreover, an exploit is present.