CVE-2016-9333

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
0.7%
top 29.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 17

Description

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5moxa_softcms_prior_to_version_1.6Moxa SoftCMS prior to Version 1.6
NVDmoxa/softcms1.5

🔴Vulnerability Details

2
GHSA
GHSA-75gf-wr4h-fm7w: An issue was discovered in Moxa SoftCMS versions prior to Version 12022-05-17
CVEList
CVE-2016-9333: An issue was discovered in Moxa SoftCMS versions prior to Version 12017-02-13
CVE-2016-9333 (CRITICAL CVSS 9.8) | An issue was discovered in Moxa Sof | cvebase.io