Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-1665

Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 82.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2012-1665
  • Oscmax » Oscmax » Version: 2.5.0
    cpe:2.3:a:oscmax:oscmax:2.5.0


Contact Us

Shodan ® - All rights reserved