Ocomon Project's vulnerability footprint centers on a single web application product and is characterized by recurring application-layer weaknesses including SQL injection, cross-site scripting, improper input neutralization, access-control flaws, and exposure of sensitive information. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ocomon Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41391CRITICAL OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-41390CRITICAL OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40798HIGH OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account t | Oct 19, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-33559HIGH A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file. | Oct 26, 2023 | 8.8 | 24 | NO | NO |
CVE-2005-4664MEDIUM SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon | Dec 31, 2005 | 5.0 | 22 | NO | YES |
CVE-2023-33558HIGH An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames. | Oct 26, 2023 | 7.5 | 21 | NO | NO |
CVE-2005-4662MEDIUM Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unsp | Dec 31, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-4663MEDIUM Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ocomon Project.
Media articles that mention a CVE ID that affects a product developed by Ocomon Project — matched by CVE ID, not by vendor name.