Lucene search

K
cvelistMitreCVELIST:CVE-2023-38330
HistoryAug 02, 2023 - 12:00 a.m.

CVE-2023-38330

2023-08-0200:00:00
mitre
www.cve.org
2
cve-2023-38330
file upload
administration area
modified headers
http response splitting

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

30.6%

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

30.6%

Related for CVELIST:CVE-2023-38330