CVE-2016-2242

Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
exponentcmsexponent_cms
2.0.0
exponentcmsexponent_cms
2.0.1
exponentcmsexponent_cms
2.0.2
exponentcmsexponent_cms
2.0.3
exponentcmsexponent_cms
2.0.4
exponentcmsexponent_cms
2.0.4:p3
exponentcmsexponent_cms
2.0.5
exponentcmsexponent_cms
2.0.5:p1
exponentcmsexponent_cms
2.0.6
exponentcmsexponent_cms
2.0.6:p2
exponentcmsexponent_cms
2.0.7
exponentcmsexponent_cms
2.0.8
exponentcmsexponent_cms
2.0.8:p2
exponentcmsexponent_cms
2.0.9
exponentcmsexponent_cms
2.0.9:p5
exponentcmsexponent_cms
2.1.0:alpha
exponentcmsexponent_cms
2.1.1
exponentcmsexponent_cms
2.1.2
exponentcmsexponent_cms
2.1.3
exponentcmsexponent_cms
2.1.4
exponentcmsexponent_cms
2.1.4:p11
exponentcmsexponent_cms
2.2.0
exponentcmsexponent_cms
2.2.0:p5
exponentcmsexponent_cms
2.2.1
exponentcmsexponent_cms
2.2.2
exponentcmsexponent_cms
2.2.2:p2
exponentcmsexponent_cms
2.2.3
exponentcmsexponent_cms
2.2.3:p14
exponentcmsexponent_cms
2.3.0
exponentcmsexponent_cms
2.3.0:p4
exponentcmsexponent_cms
2.3.1
exponentcmsexponent_cms
2.3.1:p4
exponentcmsexponent_cms
2.3.2
exponentcmsexponent_cms
2.3.2:p2
exponentcmsexponent_cms
2.3.3
exponentcmsexponent_cms
2.3.3:p1
exponentcmsexponent_cms
2.3.4
exponentcmsexponent_cms
2.3.4:p1
exponentcmsexponent_cms
2.3.5
exponentcmsexponent_cms
2.3.5:p2
exponentcmsexponent_cms
2.3.7
exponentcmsexponent_cms
2.3.8
𝑥
= Vulnerable software versions