Summary
This host is installed with OXID eShop Community Edition and is prone to Privilege Escalation vulnerability.
Impact
Attackers can exploit this issue to gain administrator privileges and access shop backend via specially crafted URLs.
Impact Level: Application
Solution
Apply the patches or upgrade to version 4.1.0
http://www.oxidforge.org/wiki/Category:Downloads
Insight
User supplied data passed to an unspecified variable is not sanitised before processing.
Affected
OXID eShop Community Edition version 4.0 prior to 4.1.0.
References
Severity
Classification
-
CVE CVE-2009-3112 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Atlassian JIRA Privilege Escalation and Multiple Cross Site Scripting Vulnerabilities
- Apache Solr XML External Entity(XXE) Vulnerability-02 Jan-14
- AlienVault OSSIM Multiple Remote Code Execution Vulnerabilities
- Apache Archiva Multiple Remote Command Execution Vulnerabilities
- Arkeia Appliance Path Traversal Vulnerability