CVE-2016-8360
published 2017-02-13CVE-2016-8360: An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double…
PriorityP341high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.07%
79.2th percentile
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the execution of arbitrary code.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | softcms | <= 1.5 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa SoftCMS Vulnerabilities
cisa_ics·2016-11-17
Moxa SoftCMS Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa SoftCMS Vulnerabilities
Last RevisedNovember 17, 2016
Alert CodeICSA-16-322-02
## OVERVIEW
Zhou Yu working with Trend Micro’s Zero Day Initiative and Gu Ziqiang from Huawei Weiran Labs have identified vulnerabilities in Moxa’s SoftCMS Webserver Application. Moxa has produced an update to mitigate these vulnerabilities. Both researchers have tested the update to validate that it resolves these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerabilities affect the following versions of SoftCMS:
- SoftCMS v
GHSA
GHSA-fcv2-47vf-j6hq: An issue was discovered in Moxa SoftCMS versions prior to Version 1
ghsa_unreviewed·2022-05-17
CVE-2016-8360 [HIGH] CWE-415 GHSA-fcv2-47vf-j6hq: An issue was discovered in Moxa SoftCMS versions prior to Version 1
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the execution of arbitrary code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published