Vulnerabilities
Vulnerable Software
Insanevisions:  >> Onecms  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view parameter.
CVSS Score
4.3
EPSS Score
0.015
Published
2011-10-07
SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.
CVSS Score
6.8
EPSS Score
0.009
Published
2010-03-10
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter.
CVSS Score
7.5
EPSS Score
0.01
Published
2009-04-07
Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter in a go action.
CVSS Score
7.5
EPSS Score
0.028
Published
2008-05-28


Contact Us

Shodan ® - All rights reserved