CVE-2016-9332
published 2017-02-13CVE-2016-9332: An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide…
PriorityP352high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
8.24%
94.3th percentile
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | softcms | <= 1.5 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-55xr-gqp7-q7ff: An issue was discovered in Moxa SoftCMS versions prior to Version 1
ghsa_unreviewed·2022-05-17
CVE-2016-9332 [HIGH] GHSA-55xr-gqp7-q7ff: An issue was discovered in Moxa SoftCMS versions prior to Version 1
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition.
CISA ICS
Moxa SoftCMS Vulnerabilities
cisa_ics·2016-11-17
Moxa SoftCMS Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa SoftCMS Vulnerabilities
Last RevisedNovember 17, 2016
Alert CodeICSA-16-322-02
## OVERVIEW
Zhou Yu working with Trend Micro’s Zero Day Initiative and Gu Ziqiang from Huawei Weiran Labs have identified vulnerabilities in Moxa’s SoftCMS Webserver Application. Moxa has produced an update to mitigate these vulnerabilities. Both researchers have tested the update to validate that it resolves these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerabilities affect the following versions of SoftCMS:
- SoftCMS v
No detection rules found.
No writeups or analysis indexed.
2017-02-13
Published