Skip to content
Noroxi

oxidforge records

4 published records for vendor oxidforge.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 18
  3. 23

Bar: total · dark part: CISA KEV.

Attack profile

All records

4 records
  • Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain adminis

    CriticalCVSS 10.0No exploitEPSS 2%

    oxidforge · oxid eshopSep 9, 2009

  • CVE-2016-5072
    36Monitor

    OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class.

    HighCVSS 8.8No exploitEPSS 2%

    oxidforge · oxid eshopApr 9, 2017

  • CVE-2014-2017
    25Monitor

    CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5

    MediumCVSS 6.1Proof of conceptEPSS 2%

    oxidforge · eshopJan 18, 2018

  • OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attac

    MediumCVSS 5.4No exploitEPSS 0%

    oxidforge · oxid eshopApr 11, 2023