CVE-2018-5763
19.02.2018, 21:29
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.Enginsight
Vendor | Product | Version |
---|---|---|
oxid-esales | eshop | 𝑥 < 5.3.7 |
oxid-esales | eshop | 6.0.0 |
oxid-esales | eshop | 6.0.0:rc1 |
oxid-esales | eshop | 6.0.0:rc2 |
oxid-esales | eshop | 6.0.0:rc3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration