Skip to content
Noroxi

osclass records

10 published records for vendor osclass.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

10 records
  • CVE-2014-8084
    31Monitor

    Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and

    HighCVSS 7.5No exploitEPSS 3%

    osclass · osclassJan 5, 2015

  • CVE-2012-0973
    31Monitor

    Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory pa

    HighCVSS 7.5Proof of conceptEPSS 2%

    osclass · osclassSep 25, 2012

  • CVE-2014-8083
    31Monitor

    SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL comm

    HighCVSS 7.5No exploitEPSS 2%

    osclass · osclassJan 5, 2015

  • osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter.

    HighCVSS 7.2No exploitEPSS 3%

    osclass · osclassMay 24, 2019

  • CVE-2014-8085
    28Monitor

    Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.

    MediumCVSS 6.8No exploitEPSS 3%

    osclass · osclassJan 5, 2015

  • CVE-2014-6308
    27Monitor

    Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0Proof of conceptEPSS 22%

    osclass · osclassOct 20, 2014

  • CVE-2012-5162
    26Monitor

    Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL com

    MediumCVSS 6.5No exploitEPSS 1%

    osclass · osclassSep 25, 2012

  • Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.

    MediumCVSS 6.1No exploitEPSS 1%

    osclass · osclassJan 3, 2019

  • CVE-2014-6280
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 4.3No exploitEPSS 2%

    osclass · osclassOct 20, 2014

  • CVE-2012-5163
    18Monitor

    Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web s

    MediumCVSS 4.3No exploitEPSS 2%

    osclass · osclassSep 25, 2012