Vulnerability CVE-2014-2017


Published: 2018-01-18

Description:
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
OXID eShop XSS / CRLF Injection
//sToRm
21.03.2014

Type:

CWE-93

(Improper Neutralization of CRLF Sequences ('CRLF Injection'))

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.8/10
4.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None

 References:
https://bugs.oxid-esales.com/view.php?id=5635
https://oxidforge.org/en/security-bulletin-2014-002.html

Copyright 2024, cxsecurity.com

 

Back to Top