CVE-2023-38330
EUVD-2023-4214802.08.2023, 15:15
OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| oxid-esales | eshop | 6.5.0 ≤ 𝑥 < 6.5.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration