Vulnerabilities
Vulnerable Software
Auracms:  >> Auracms  >> 1.61  Security Vulnerabilities
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.
CVSS Score
6.5
EPSS Score
0.027
Published
2014-02-11
Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs.
CVSS Score
6.8
EPSS Score
0.013
Published
2007-09-14


Contact Us

Shodan ® - All rights reserved