CVE-2014-8084: Osclass
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ajaxfile parameter in a custom action.
Affected products
- Osclass Osclass: up to and including 3.4.2
Published 2015-01-05. Last modified 2026-06-17.