Vulnerability Description
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oxidforge | Oxid Eshop | <= 4.9.8 |
Related Weaknesses (CWE)
References
- https://oxidforge.org/en/security-bulletin-2016-001.htmlMitigationPatchVendor Advisory
- https://oxidforge.org/en/security-bulletin-2016-001.htmlMitigationPatchVendor Advisory
FAQ
What is CVE-2016-5072?
CVE-2016-5072 is a vulnerability with a CVSS score of 8.8 (HIGH). OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, ...
How severe is CVE-2016-5072?
CVE-2016-5072 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5072?
Check the references section above for vendor advisories and patch information. Affected products include: Oxidforge Oxid Eshop.