osclass records
10 published records for vendor osclass.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2014-8084No exploit | Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and osclass · osclass · CWE-22 | High7.5 | — | 3.2% | Jan 5, 2015 |
31Monitor | CVE-2012-0973Proof of concept | Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory paosclass · osclass · CWE-89 | High7.5 | — | 2.4% | Sep 25, 2012 |
31Monitor | CVE-2014-8083No exploit | SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commosclass · osclass · CWE-89 | High7.5 | — | 2.4% | Jan 5, 2015 |
29Monitor | CVE-2016-10751No exploit | osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter.osclass · osclass · CWE-22 | High7.2 | — | 2.8% | May 24, 2019 |
28Monitor | CVE-2014-8085No exploit | Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.osclass · osclass | Medium6.8 | — | 2.5% | Jan 5, 2015 |
27Monitor | CVE-2014-6308Proof of concept | Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a ..osclass · osclass · CWE-22 | Medium5.0 | — | 22.3% | Oct 20, 2014 |
26Monitor | CVE-2012-5162No exploit | Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL comosclass · osclass · CWE-89 | Medium6.5 | — | 1.0% | Sep 25, 2012 |
24Monitor | CVE-2018-14481No exploit | Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.osclass · osclass · CWE-79 | Medium6.1 | — | 1.1% | Jan 3, 2019 |
18Monitor | CVE-2014-6280No exploit | Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML viosclass · osclass · CWE-79 | Medium4.3 | — | 1.9% | Oct 20, 2014 |
18Monitor | CVE-2012-5163No exploit | Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web sosclass · osclass · CWE-79 | Medium4.3 | — | 1.8% | Sep 25, 2012 |
- CVE-2014-808431Monitor
Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and
HighCVSS 7.5No exploitEPSS 3%osclass · osclassJan 5, 2015
- CVE-2012-097331Monitor
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory pa
HighCVSS 7.5Proof of conceptEPSS 2%osclass · osclassSep 25, 2012
- CVE-2014-808331Monitor
SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5No exploitEPSS 2%osclass · osclassJan 5, 2015
- CVE-2016-1075129Monitor
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter.
HighCVSS 7.2No exploitEPSS 3%osclass · osclassMay 24, 2019
- CVE-2014-808528Monitor
Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.
MediumCVSS 6.8No exploitEPSS 3%osclass · osclassJan 5, 2015
- CVE-2014-630827Monitor
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 22%osclass · osclassOct 20, 2014
- CVE-2012-516226Monitor
Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL com
MediumCVSS 6.5No exploitEPSS 1%osclass · osclassSep 25, 2012
- CVE-2018-1448124Monitor
Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.
MediumCVSS 6.1No exploitEPSS 1%osclass · osclassJan 3, 2019
- CVE-2014-628018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 2%osclass · osclassOct 20, 2014
- CVE-2012-516318Monitor
Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web s
MediumCVSS 4.3No exploitEPSS 2%osclass · osclassSep 25, 2012