Vulnerabilities
Vulnerable Software
4pace:  >> Cadclick  Security Vulnerabilities
A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter.
CVSS Score
3.9
EPSS Score
0.0
Published
2024-10-04
A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.
CVSS Score
8.8
EPSS Score
0.003
Published
2024-10-04
A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-10-04
A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-10-04
A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-10-04
A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-10-04


Contact Us

Shodan ® - All rights reserved