CVE-2016-8360: Moxa Softcms
High severity, CVSS 8.1. EPSS: 2.1% chance of exploitation in the next 30 days.
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the execution of arbitrary code.
Affected products
- Moxa Softcms: up to and including 1.5
Published 2017-02-13. Last modified 2026-06-17.