CVE-2014-2016
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4 allow remote attackers to inject arbitrary web script or HTML via the searchtag parameter to the getTag function in (1) application/controllers/details.php or (2) application/controllers/tag.php.
Affected (9)
Products: Oxid Esales: Eshop
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.6.8 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.6.8 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.6.8 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.