Vulnerabilities > Oxidforge

DATE CVE VULNERABILITY TITLE RISK
2023-04-11 CVE-2023-26260 Unspecified vulnerability in Oxidforge Oxid Eshop
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.
network
low complexity
oxidforge
5.4
2018-01-18 CVE-2014-2017 CRLF Injection vulnerability in Oxidforge Eshop
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
network
low complexity
oxidforge CWE-93
6.1
2017-04-10 CVE-2016-5072 Code Injection vulnerability in Oxidforge Oxid Eshop 4.9.8/5.2.8
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class.
network
low complexity
oxidforge CWE-94
8.8