phpmywind kayıtları
phpmywind üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2020-21060İstismar yok | SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administratophpmywind · phpmywind · CWE-89 | Yüksek8,8 | — | %0,9 | 4 Nis 2023 |
29İzleyin | CVE-2020-18885İstismar yok | Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/wephpmywind · phpmywind · CWE-77 | Yüksek7,2 | — | %3,6 | 20 Ağu 2021 |
29İzleyin | CVE-2021-39503İstismar yok | PHPMyWind 5.6 is vulnerable to Remote Code Execution.phpmywind · phpmywind · CWE-94 | Yüksek7,2 | — | %2,8 | 7 Eyl 2021 |
29İzleyin | CVE-2018-17134İstismar yok | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfphpmywind · phpmywind · CWE-94 | Yüksek7,2 | — | %2,1 | 17 Eyl 2018 |
29İzleyin | CVE-2018-17133İstismar yok | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.phpmywind · phpmywind · CWE-94 | Yüksek7,2 | — | %2,1 | 17 Eyl 2018 |
29İzleyin | CVE-2018-17131İstismar yok | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.phpmywind · phpmywind · CWE-94 | Yüksek7,2 | — | %2,1 | 17 Eyl 2018 |
29İzleyin | CVE-2018-17132İstismar yok | admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.phpmywind · phpmywind · CWE-94 | Yüksek7,2 | — | %2,1 | 17 Eyl 2018 |
29İzleyin | CVE-2020-18886İstismar yok | Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.phpmywind · phpmywind · CWE-434 | Yüksek7,2 | — | %1,8 | 20 Ağu 2021 |
28İzleyin | CVE-2020-21400İstismar yok | SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modiphpmywind · phpmywind · CWE-89 | Yüksek7,2 | — | %1,1 | 20 Haz 2023 |
26İzleyin | CVE-2020-19964İstismar yok | A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator accouphpmywind · phpmywind · CWE-352 | Orta6,5 | — | %0,5 | 14 Eki 2021 |
25İzleyin | CVE-2017-12984Kavram kanıtı | PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.phpmywind · phpmywind · CWE-79 | Orta6,1 | — | %2,2 | 21 Ağu 2017 |
24İzleyin | CVE-2019-7661İstismar yok | An issue was discovered in PHPMyWind 5.5.phpmywind · phpmywind · CWE-79 | Orta6,1 | — | %0,9 | 7 Mar 2019 |
24İzleyin | CVE-2019-7660İstismar yok | An issue was discovered in PHPMyWind 5.5.phpmywind · phpmywind · CWE-79 | Orta6,1 | — | %0,9 | 7 Mar 2019 |
24İzleyin | CVE-2019-16703İstismar yok | admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.phpmywind · phpmywind · CWE-79 | Orta6,1 | — | %0,8 | 23 Eyl 2019 |
24İzleyin | CVE-2018-11487İstismar yok | PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.phpmywind · phpmywind · CWE-79 | Orta6,1 | — | %0,8 | 26 May 2018 |
24İzleyin | CVE-2019-7402İstismar yok | An issue was discovered in PHPMyWind 5.5.phpmywind · phpmywind · CWE-79 | Orta6,1 | — | %0,4 | 5 Şub 2019 |
21İzleyin | CVE-2018-17130İstismar yok | PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,phpmywind · phpmywind · CWE-79 | Orta5,4 | — | %0,6 | 17 Eyl 2018 |
20İzleyin | CVE-2019-7403İstismar yok | An issue was discovered in PHPMyWind 5.5.phpmywind · phpmywind · CWE-22 | Orta4,9 | — | %1,7 | 5 Şub 2019 |
19İzleyin | CVE-2020-18230İstismar yok | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfgphpmywind · phpmywind · CWE-79 | Orta4,8 | — | %1,0 | 27 May 2021 |
19İzleyin | CVE-2020-18229İstismar yok | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfgphpmywind · phpmywind · CWE-79 | Orta4,8 | — | %0,9 | 27 May 2021 |
19İzleyin | CVE-2019-16704İstismar yok | admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.phpmywind · phpmywind · CWE-79 | Orta4,8 | — | %0,7 | 23 Eyl 2019 |
19İzleyin | CVE-2019-8435İstismar yok | admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.phpmywind · phpmywind · CWE-79 | Orta4,8 | — | %0,6 | 17 Şub 2019 |
- CVE-2020-2106035İzleyin
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrato
YüksekCVSS 8,8İstismar yokEPSS %1phpmywind · phpmywind4 Nis 2023
- CVE-2020-1888529İzleyin
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/we
YüksekCVSS 7,2İstismar yokEPSS %4phpmywind · phpmywind20 Ağu 2021
- CVE-2021-3950329İzleyin
PHPMyWind 5.6 is vulnerable to Remote Code Execution.
YüksekCVSS 7,2İstismar yokEPSS %3phpmywind · phpmywind7 Eyl 2021
- CVE-2018-1713429İzleyin
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cf
YüksekCVSS 7,2İstismar yokEPSS %2phpmywind · phpmywind17 Eyl 2018
- CVE-2018-1713329İzleyin
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
YüksekCVSS 7,2İstismar yokEPSS %2phpmywind · phpmywind17 Eyl 2018
- CVE-2018-1713129İzleyin
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
YüksekCVSS 7,2İstismar yokEPSS %2phpmywind · phpmywind17 Eyl 2018
- CVE-2018-1713229İzleyin
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
YüksekCVSS 7,2İstismar yokEPSS %2phpmywind · phpmywind17 Eyl 2018
- CVE-2020-1888629İzleyin
Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.
YüksekCVSS 7,2İstismar yokEPSS %2phpmywind · phpmywind20 Ağu 2021
- CVE-2020-2140028İzleyin
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modi
YüksekCVSS 7,2İstismar yokEPSS %1phpmywind · phpmywind20 Haz 2023
- CVE-2020-1996426İzleyin
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator accou
OrtaCVSS 6,5İstismar yokEPSS %1phpmywind · phpmywind14 Eki 2021
- CVE-2017-1298425İzleyin
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
OrtaCVSS 6,1Kavram kanıtıEPSS %2phpmywind · phpmywind21 Ağu 2017
- CVE-2019-766124İzleyin
An issue was discovered in PHPMyWind 5.5.
OrtaCVSS 6,1İstismar yokEPSS %1phpmywind · phpmywind7 Mar 2019
- CVE-2019-766024İzleyin
An issue was discovered in PHPMyWind 5.5.
OrtaCVSS 6,1İstismar yokEPSS %1phpmywind · phpmywind7 Mar 2019
- CVE-2019-1670324İzleyin
admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.
OrtaCVSS 6,1İstismar yokEPSS %1phpmywind · phpmywind23 Eyl 2019
- CVE-2018-1148724İzleyin
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
OrtaCVSS 6,1İstismar yokEPSS %1phpmywind · phpmywind26 May 2018
- CVE-2019-740224İzleyin
An issue was discovered in PHPMyWind 5.5.
OrtaCVSS 6,1İstismar yokEPSS %0phpmywind · phpmywind5 Şub 2019
- CVE-2018-1713021İzleyin
PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
OrtaCVSS 5,4İstismar yokEPSS %1phpmywind · phpmywind17 Eyl 2018
- CVE-2019-740320İzleyin
An issue was discovered in PHPMyWind 5.5.
OrtaCVSS 4,9İstismar yokEPSS %2phpmywind · phpmywind5 Şub 2019
- CVE-2020-1823019İzleyin
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg
OrtaCVSS 4,8İstismar yokEPSS %1phpmywind · phpmywind27 May 2021
- CVE-2020-1822919İzleyin
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg
OrtaCVSS 4,8İstismar yokEPSS %1phpmywind · phpmywind27 May 2021
- CVE-2019-1670419İzleyin
admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.
OrtaCVSS 4,8İstismar yokEPSS %1phpmywind · phpmywind23 Eyl 2019
- CVE-2019-843519İzleyin
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
OrtaCVSS 4,8İstismar yokEPSS %1phpmywind · phpmywind17 Şub 2019