CVE-2016-5792
published 2016-08-08CVE-2016-5792: SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.
PriorityP358critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.04%
86.0th percentile
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | softcms | <= 1.4 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2jqr-pg96-vppj: SQL injection vulnerability in Moxa SoftCMS before 1
ghsa_unreviewed·2022-05-17
CVE-2016-5792 [CRITICAL] CWE-89 GHSA-2jqr-pg96-vppj: SQL injection vulnerability in Moxa SoftCMS before 1
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.
CISA ICS
Moxa SoftCMS SQL Injection Vulnerability
cisa_ics·2018-08-23
Moxa SoftCMS SQL Injection Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa SoftCMS SQL Injection Vulnerability
Last RevisedAugust 23, 2018
Alert CodeICSA-16-215-01
## OVERVIEW
Zhou Yu of Acorn Network Security has identified a SQL injection vulnerability in Moxa's SoftCMS. ZDI reported this vulnerability to ICS-CERT. Moxa has produced an update to mitigate this vulnerability.
This vulnerability could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerability affects the following products:
- SoftCMS versions prior to Version 1.5
## IMPACT
A successful exploit of this vulnerability could allow an attacker to execute arbit
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-08-08
Published