Insane Visions Onecms vulnerabilities
3 known vulnerabilities affecting insane_visions/onecms.
Total CVEs
3
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2008-7209P3HIGHCVSS 7.5PoC≤ 2.42009-09-11
CVE-2008-7209 [HIGH] CWE-264 CVE-2008-7209: Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibl
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as image/gif, then accessing it via a direct request to the file in an unspecified directory.
nvd
CVE-2008-7208P3MEDIUMCVSS 6.8PoC≤ 2.42009-09-11
CVE-2008-7208 [MEDIUM] CWE-89 CVE-2008-7208: Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers t
Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php.
nvd
CVE-2007-5016P3HIGHCVSS 7.5PoCv2.42007-09-20
CVE-2007-5016 [HIGH] CWE-89 CVE-2007-5016: SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbi
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.
nvd