Oxid-esales

Eshop

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 13.05.2025 00:00:00
  • Zuletzt bearbeitet 29.01.2026 20:47:53

An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.

  • EPSS 0.16%
  • Veröffentlicht 02.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:20

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.

  • EPSS 0.46%
  • Veröffentlicht 05.11.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:37

An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a ...

  • EPSS 0.33%
  • Veröffentlicht 30.07.2019 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:03

OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the ...

  • EPSS 0.26%
  • Veröffentlicht 15.01.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:01

The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php.

  • EPSS 0.4%
  • Veröffentlicht 20.08.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:28

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6....

Exploit
  • EPSS 0.35%
  • Veröffentlicht 20.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:09:26

OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), ...

  • EPSS 0.64%
  • Veröffentlicht 20.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:13:54

OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), ...

  • EPSS 0.5%
  • Veröffentlicht 19.02.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:20

An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High ...

  • EPSS 0.19%
  • Veröffentlicht 19.01.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 02:11:07

OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical us...