Memory Modification Vulnerability in Moxa SoftCMS Webserver
CVE-2016-8360

8.1HIGH

Key Information:

Vendor
Moxa
Vendor
CVE Published:
13 February 2017

Summary

A vulnerability exists in Moxa SoftCMS prior to version 1.6, where an attacker can exploit a specially crafted URL request sent to the SoftCMS ASP Webserver. This can lead to a double free condition, enabling the modification of memory locations, which may result in denial of service attacks or the execution of arbitrary code, thus compromising the security of the affected systems.

Affected Version(s)

Moxa SoftCMS prior to Version 1.6 Moxa SoftCMS prior to Version 1.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.