vendor:
OXID eShop
by:
VulnSpy
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OXID eShop
Affected Version From: 6.x (prior to 6.3.4)
Affected Version To: 6.3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:oxid_esales:oxid_eshop
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
OXID eShop 6.3.4 – ‘sorting’ SQL Injection
OXID eShop is vulnerable to a SQL Injection vulnerability in the 'sorting' parameter. By adding the 'sorting' parameter after the URL of an item detail page, an attacker can insert malicious PHP code into the database. This code can then be executed by accessing a specially crafted URL, which will display the PHPINFO page if exploited successfully.
Mitigation:
Upgrade to OXID eShop version 6.3.4 or later.