Vulnerabilities
Vulnerable Software
Auracms:  >> Auracms  >> 2.2.1  Security Vulnerabilities
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.
CVSS Score
6.5
EPSS Score
0.027
Published
2014-02-11
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
CVSS Score
7.5
EPSS Score
0.024
Published
2008-07-17
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.
CVSS Score
6.8
EPSS Score
0.003
Published
2008-03-20


Contact Us

Shodan ® - All rights reserved