CVE-2009-2266

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
09/09/2009
Last modified:
09/04/2025

Description

OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oxid:eshop:*:*:enterprise:*:*:*:*:* 2.7.0.3 (including)
cpe:2.3:a:oxid:eshop:*:*:professional:*:*:*:*:* 3.0.4.1 (including)
cpe:2.3:a:oxid:eshop:4.0.0.0_13895:*:community:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_13895:*:enterprise:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_13895:*:professional:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_13934:*:community:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_13934:*:enterprise:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_13934:*:professional:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_14260:*:community:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_14260:*:enterprise:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.0_14260:*:professional:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.1_14455:*:community:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.1_14455:*:enterprise:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.1_14455:*:professional:*:*:*:*:*
cpe:2.3:a:oxid:eshop:4.0.0.2_14842:*:community:*:*:*:*:*