CVE Browser

More filters (active)
CVE-2016-10751 HIGH

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administra…

CVSS 7.2 EPSS 2.81% May 24, 2019
CVE-2018-14481 MEDIUM

Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.

CVSS 6.1 EPSS 1.08% Jan 3, 2019
CVE-2014-8085 MEDIUM

Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote a…

CVSS 6.8 EPSS 2.51% Jan 5, 2015
CVE-2014-8084 HIGH

Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary l…

CVSS 7.5 EPSS 3.25% Jan 5, 2015
CVE-2014-8083 HIGH

SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert…

CVSS 7.5 EPSS 2.36% Jan 5, 2015
CVE-2014-6308 MEDIUM

Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render…

CVSS 5.0 EPSS 22.26% Oct 20, 2014
CVE-2014-6280 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action or…

CVSS 4.3 EPSS 1.89% Oct 20, 2014
CVE-2012-5163 MEDIUM

Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via t…

CVSS 4.3 EPSS 1.79% Sep 26, 2012
CVE-2012-5162 MEDIUM

Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the id pa…

CVSS 6.5 EPSS 1.04% Sep 26, 2012
CVE-2012-0973 HIGH

Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.ph…

CVSS 7.5 EPSS 2.41% Sep 25, 2012

Showing 1 to 10 CVEs · page 1