Product
osclass
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-27515
CVE-2016-10751
CVE-2018-14481
CVE-2014-8085
CVE-2014-8084
CVE-2014-8083
CVE-2014-6308
CVE-2014-6280
CVE-2012-5163
CVE-2012-5162
CVE-2012-1617
CVE-2012-0974
CVE-2012-0973
all versions
Osclass 5.1.2 is vulnerable to SQL Injection.
all versions
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code ex
all versions
Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.
<= 3.4.2
Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass
<= 3.4.2
Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to in
<= 3.4.2
SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrar
<= 3.4.1
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in th
<= 3.4.1
Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script
<= 2.3.4
Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbit
<= 2.3.4
Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitra
<= 2.3.5
Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files
<= 2.3.4
Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass bef
<= 2.3.4
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sC