OXID eShop 6.3.4 - 'sorting' SQL Injection
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8epss 0.4%
probabilidad de explotación
0.4%top 67% de las CVE
explotación observada
noninguna fuente lo reporta
OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
OXID-eSales · OXID eShopReferencias
https://bugs.oxid-esales.com/view.php?id=7002https://github.com/OXID-eSales/oxideshop_cehttps://web.archive.org/web/20190731211638/https://blog.ripstech.com/2019/oxid-esales-shop-software/https://web.archive.org/web/20201020223434/https://www.vulnspy.com/en-oxid-eshop-6.x-sqli-to-rce/https://www.exploit-db.com/exploits/48527https://www.oxid-esales.com/https://www.vulncheck.com/advisories/oxid-eshop-sorting-sql-injection