Vulnerabilities
Vulnerable Software
Nuuo:  >> Nuuo Cms  >> 3.3  Security Vulnerabilities
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.678
Published
2018-11-27
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.
CVSS Score
9.8
EPSS Score
0.672
Published
2018-11-27
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.668
Published
2018-11-27


Contact Us

Shodan ® - All rights reserved