Onecms
Insanevisions · 7 CVEs
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web s…
Oct 7, 2011
SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to e…
Mar 9, 2010
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows r…
Sep 11, 2009
Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary…
Sep 11, 2009
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the…
Apr 7, 2009
Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and…
May 28, 2008
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands…
Sep 20, 2007
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2010-4877 | Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter. | MEDIUM | 1.50% | Oct 7, 2011 |
| CVE-2010-0952 | SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the us… | MEDIUM | 0.94% | Mar 9, 2010 |
| CVE-2008-7209 | Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary cod… | HIGH | 6.01% | Sep 11, 2009 |
| CVE-2008-7208 | Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username param… | MEDIUM | 1.77% | Sep 11, 2009 |
| CVE-2008-6652 | SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter. | HIGH | 0.97% | Apr 7, 2009 |
| CVE-2008-2482 | Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a ..… | HIGH | 2.84% | May 28, 2008 |
| CVE-2007-5016 | SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter. | HIGH | 1.02% | Sep 20, 2007 |
Showing 1 to 7 of 7 CVEs