CVE-2016-9333
published 2017-02-13CVE-2016-9333: An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote…
PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.88%
77.3th percentile
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | softcms | <= 1.5 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa SoftCMS Vulnerabilities
cisa_ics·2016-11-17
Moxa SoftCMS Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa SoftCMS Vulnerabilities
Last RevisedNovember 17, 2016
Alert CodeICSA-16-322-02
## OVERVIEW
Zhou Yu working with Trend Micro’s Zero Day Initiative and Gu Ziqiang from Huawei Weiran Labs have identified vulnerabilities in Moxa’s SoftCMS Webserver Application. Moxa has produced an update to mitigate these vulnerabilities. Both researchers have tested the update to validate that it resolves these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerabilities affect the following versions of SoftCMS:
- SoftCMS v
GHSA
GHSA-75gf-wr4h-fm7w: An issue was discovered in Moxa SoftCMS versions prior to Version 1
ghsa_unreviewed·2022-05-17
CVE-2016-9333 [CRITICAL] CWE-89 GHSA-75gf-wr4h-fm7w: An issue was discovered in Moxa SoftCMS versions prior to Version 1
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published