vendor:
Osclass
by:
SecurityFocus
7,5
CVSS
HIGH
Cross-site request forgery, Directory Traversal, SQL Injection
352, 22, 89
CWE
Product Name: Osclass
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:osclass:osclass
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache
2013
Osclass Multiple Vulnerabilities
Osclass is prone to multiple input-validation vulnerabilities, including a cross-site request-forgery vulnerability, multiple directory-traversal vulnerabilities, and an SQL-injection vulnerability. Exploiting these issues may allow a remote attacker to perform certain unauthorized actions, to view arbitrary local files and directories within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible. Proof of concept code is provided for each vulnerability.
Mitigation:
Users should apply the latest available updates to the affected application.