CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
References
Link Resource
https://bugs.oxid-esales.com/view.php?id=5635 Issue Tracking Vendor Advisory
https://oxidforge.org/en/security-bulletin-2014-002.html Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-18T14:00:00

Updated: 2018-01-18T13:57:01

Reserved: 2014-02-17T00:00:00


Link: CVE-2014-2017

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-01-18T14:29:00.227

Modified: 2018-02-06T17:28:57.800


Link: CVE-2014-2017

JSON object: View

cve-icon Redhat Information

No data.

CWE