Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Osclass HIGH 7.2
CVE-2016-10751

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an …

Mitigation only
Fix from $1,950 2019-05-24
Osclass MEDIUM 6.1
CVE-2018-14481

Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.

No fix yet
Fix from $1,600 2019-01-03
Osclass MEDIUM 6.8
CVE-2014-8085

Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allow…

Fix: after 3.4.2
Fix from $1,600 2015-01-05
Osclass HIGH 7.5
CVE-2014-8084

Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute a…

Fix: after 3.4.2
Fix from $1,950 2015-01-05
Osclass HIGH 7.5
CVE-2014-8083

SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via …

Fix: after 3.4.2
Fix from $1,950 2015-01-05
Osclass MEDIUM 5.0
CVE-2014-6308EPSS 22%

Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in…

Fix: after 3.4.1
Fix from $1,600 2014-10-20
Osclass MEDIUM 6.5
CVE-2012-5162

Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via…

Fix: after 2.3.4
Fix from $1,600 2012-09-26
Osclass HIGH 7.5
CVE-2012-0973

Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter t…

Fix: after 2.3.4
Fix from $1,950 2012-09-25