4.3
CVSSv2

CVE-2014-2016

Published: 25/03/2014 Updated: 19/03/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and previous versions, 4.7.x prior to 4.7.11, and 4.8.x prior to 4.8.4, and Enterprise Edition 4.6.8 and previous versions, 5.0.x prior to 5.0.11 and 5.1.x prior to 5.1.4 allow remote malicious users to inject arbitrary web script or HTML via the searchtag parameter to the getTag function in (1) application/controllers/details.php or (2) application/controllers/tag.php.

Vulnerable Product Search on Vulmon Subscribe to Product

oxid-esales eshop

Exploits

# Exploit Title: OXID eShop v<4711/5011 + v<484/514 Multiple Vulnerabilities # Google Dork: - # Date: 12/2013 # Exploit Author: //sToRm # Author mail: storm@sicherheit-onlineorg # Vendor Homepage: wwwoxid-esalescom # Software Link: - # Version: All versions < 4711/5011 + All versions < 484/514 # Tested on: Mu ...
OXID eSHOP versions prior to 4711/5011 and 484/514 suffer from cross site scripting and CRLF injection vulnerabilities ...