CVE-2018-5763

An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.
References
Link Resource
https://oxidforge.org/en/security-bulletin-2018-001.html Mitigation Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oxid-esales:eshop:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:oxid-esales:eshop:6.0.0:rc1:*:*:enterprise:*:*:*
cpe:2.3:a:oxid-esales:eshop:6.0.0:rc2:*:*:enterprise:*:*:*
cpe:2.3:a:oxid-esales:eshop:6.0.0:rc3:*:*:enterprise:*:*:*
cpe:2.3:a:oxid-esales:eshop:6.0.0:*:*:*:enterprise:*:*:*

Information

Published : 2018-02-19 13:29

Updated : 2018-03-20 10:26


NVD link : CVE-2018-5763

Mitre link : CVE-2018-5763


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

oxid-esales

  • eshop