View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0002222 | OXID eShop (all versions) | 4.04. Security | public | 2010-11-24 10:31 | 2010-12-13 13:21 |
Reporter | dainius.bigelis | Assigned To | |||
Priority | urgent | Severity | major | Reproducibility | always |
Status | resolved | Resolution | fixed | ||
Product Version | 4.4.4 revision 30554 | ||||
Fixed in Version | 4.4.5 revision 31315 | ||||
Summary | 0002222: Improper handling of quotes in eShop input field | ||||
Description | By specially crafted JavaScript code, inserted in particular input fields in OXID eShop frontend, it's possible to execute unauthorized JavaScript code in eShop admin area. | ||||
Tags | No tags attached. | ||||
Theme | |||||
Browser | All | ||||
PHP Version | any | ||||
Database Version | any | ||||
related to | 0002206 | resolved | alfonsas_cirtautas | Improper reading of Tags from DB |