Lucene search

K
prionPRIOn knowledge basePRION:CVE-2012-1665
HistoryMay 20, 2015 - 6:59 p.m.

Sql injection

2015-05-2018:59:00
PRIOn knowledge base
www.prio-n.com
3

9.1 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.1%

Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.

CPENameOperatorVersion
oscmaxle2.5.0

9.1 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.1%