Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2016-10751

    osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

    Last Modified: Nov 21, 2024
    Published: May 24, 2019

    CVE-2018-14481

    Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.

    Last Modified: Nov 21, 2024
    Published: Jan 03, 2019

    CVE-2014-8085

    Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory.

    Last Modified: Apr 12, 2025
    Published: Jan 05, 2015

    CVE-2014-8084

    Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ajaxfile parameter in a custom action.

    Last Modified: Apr 12, 2025
    Published: Jan 05, 2015

    CVE-2014-8083

    SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action.

    Last Modified: Apr 12, 2025
    Published: Jan 05, 2015
    Items Per Page
    Osclass Vulnerabilities & Security CVEs | CVE-DB