Arbitrary Code Execution Vulnerability in OXID eShop (CVE-2016-XXXX)

Arbitrary Code Execution Vulnerability in OXID eShop (CVE-2016-XXXX)

CVE-2016-5072 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9.

Learn more about our User Device Pen Test.