CVE-2023-38330
02.08.2023, 15:15
OXID eShop Enterprise Edition 6.5.0 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.Enginsight
Vendor | Product | Version |
---|---|---|
oxid-esales | eshop | 6.5.0 ≤ 𝑥 < 6.5.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration