Vulnerabilities
Vulnerable Software
Auracms:  >> Auracms  >> 2.2  Security Vulnerabilities
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.
CVSS Score
6.5
EPSS Score
0.027
Published
2014-02-11
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
CVSS Score
7.5
EPSS Score
0.024
Published
2008-07-17
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.
CVSS Score
10.0
EPSS Score
0.003
Published
2008-02-13
Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.
CVSS Score
6.0
EPSS Score
0.018
Published
2007-12-28


Contact Us

Shodan ® - All rights reserved