View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0002222 | OXID eShop (all versions) | 4.04. Security | public | 2010-11-24 10:31 | 2010-12-13 13:21 |
| Reporter | dainius.bigelis | Assigned To | |||
| Priority | urgent | Severity | major | Reproducibility | always |
| Status | resolved | Resolution | fixed | ||
| Product Version | 4.4.4 revision 30554 | ||||
| Fixed in Version | 4.4.5 revision 31315 | ||||
| Summary | 0002222: Improper handling of quotes in eShop input field | ||||
| Description | By specially crafted JavaScript code, inserted in particular input fields in OXID eShop frontend, it's possible to execute unauthorized JavaScript code in eShop admin area. | ||||
| Tags | No tags attached. | ||||
| Theme | |||||
| Browser | All | ||||
| PHP Version | any | ||||
| Database Version | any | ||||
| related to | 0002206 | resolved | alfonsas_cirtautas | Improper reading of Tags from DB |