6.1
CVSSv3

CVE-2014-2017

Published: 18/01/2018 Updated: 06/02/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in OXID eShop Professional Edition prior to 4.7.11 and 4.8.x prior to 4.8.4, Enterprise Edition prior to 5.0.11 and 5.1.x prior to 5.1.4, and Community Edition prior to 4.7.11 and 4.8.x prior to 4.8.4 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

oxidforge eshop

Exploits

# Exploit Title: OXID eShop v<4711/5011 + v<484/514 Multiple Vulnerabilities # Google Dork: - # Date: 12/2013 # Exploit Author: //sToRm # Author mail: storm@sicherheit-onlineorg # Vendor Homepage: wwwoxid-esalescom # Software Link: - # Version: All versions < 4711/5011 + All versions < 484/514 # Tested on: Mu ...
OXID eSHOP versions prior to 4711/5011 and 484/514 suffer from cross site scripting and CRLF injection vulnerabilities ...