Записи MingSoft
48 опубликованных записей вендора mingsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 16
- С записью об исправлении
- 22,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-434 Unrestricted Upload of File with Dangerous Type12
- CWE-707 Improper Neutralization3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
48 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2022-22930Эксплойта нет | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code vimingsoft · mcms | Критическая9,8 | — | 23,7 % | 20 янв. 2022 г. |
41В плане | CVE-2022-23898Proof of concept | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 7,7 % | 3 мар. 2022 г. |
41В плане | CVE-2022-25125Proof of concept | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 7,0 % | 3 мар. 2022 г. |
41В плане | CVE-2022-26585Proof of concept | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 5,5 % | 4 апр. 2022 г. |
40В плане | CVE-2024-22567Эксплойта нет | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.mingsoft · mcms · CWE-434 | Высокая8,8 | — | 17,8 % | 5 февр. 2024 г. |
40В плане | CVE-2021-46036Эксплойта нет | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary codemingsoft · mcms · CWE-434 | Критическая9,8 | — | 3,7 % | 18 февр. 2022 г. |
40В плане | CVE-2021-46386Эксплойта нет | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to nmingsoft · mcms · CWE-434 | Критическая9,8 | — | 3,1 % | 26 янв. 2022 г. |
40В плане | CVE-2022-4375Proof of concept | Mingsoft MCMS list sql injectionmingsoft · mcms · CWE-707 | Критическая9,8 | — | 3,0 % | 9 дек. 2022 г. |
40В плане | CVE-2022-22929Эксплойта нет | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbimingsoft · mcms · CWE-434 | Критическая9,8 | — | 2,6 % | 20 янв. 2022 г. |
40В плане | CVE-2022-30506Эксплойта нет | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP fimingsoft · mcms · CWE-434 | Критическая9,8 | — | 2,6 % | 2 июн. 2022 г. |
40В плане | CVE-2022-22928Эксплойта нет | MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.mingsoft · mcms · CWE-798 | Критическая9,8 | — | 2,5 % | 20 янв. 2022 г. |
40В плане | CVE-2023-50578Proof of concept | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 2,2 % | 30 дек. 2023 г. |
40В плане | CVE-2021-46384Эксплойта нет | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.mingsoft · mcms · CWE-306 | Критическая9,8 | — | 2,2 % | 4 мар. 2022 г. |
40В плане | CVE-2022-23315Эксплойта нет | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.mingsoft · mcms · CWE-434 | Критическая9,8 | — | 1,8 % | 20 янв. 2022 г. |
39Наблюдать | CVE-2022-27466Эксплойта нет | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,6 % | 2 мая 2022 г. |
39Наблюдать | CVE-2022-23314Эксплойта нет | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,6 % | 20 янв. 2022 г. |
39Наблюдать | CVE-2022-31943Эксплойта нет | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.mingsoft · mcms · CWE-434 | Критическая9,8 | — | 1,5 % | 1 июл. 2022 г. |
39Наблюдать | CVE-2022-30047Эксплойта нет | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,4 % | 11 мая 2022 г. |
39Наблюдать | CVE-2022-30048Эксплойта нет | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,4 % | 11 мая 2022 г. |
39Наблюдать | CVE-2020-20913Эксплойта нет | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,4 % | 4 апр. 2023 г. |
39Наблюдать | CVE-2021-44868Эксплойта нет | A problem was found in ming-soft MCMS v5.1.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,4 % | 17 февр. 2022 г. |
39Наблюдать | CVE-2018-18830Эксплойта нет | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.mingsoft · mcms · CWE-434 | Критическая9,8 | — | 1,2 % | 30 окт. 2018 г. |
39Наблюдать | CVE-2020-23262Эксплойта нет | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,1 % | 26 янв. 2021 г. |
39Наблюдать | CVE-2022-36272Эксплойта нет | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,1 % | 16 авг. 2022 г. |
39Наблюдать | CVE-2022-36599Эксплойта нет | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.mingsoft · mcms · CWE-89 | Критическая9,8 | — | 1,1 % | 16 авг. 2022 г. |
- CVE-2022-2293046В плане
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code vi
КритическаяCVSS 9,8Эксплойта нетEPSS 24 %mingsoft · mcms20 янв. 2022 г.
- CVE-2022-2389841В плане
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
КритическаяCVSS 9,8Proof of conceptEPSS 8 %mingsoft · mcms3 мар. 2022 г.
- CVE-2022-2512541В плане
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
КритическаяCVSS 9,8Proof of conceptEPSS 7 %mingsoft · mcms3 мар. 2022 г.
- CVE-2022-2658541В плане
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %mingsoft · mcms4 апр. 2022 г.
- CVE-2024-2256740В плане
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
ВысокаяCVSS 8,8Эксплойта нетEPSS 18 %mingsoft · mcms5 февр. 2024 г.
- CVE-2021-4603640В плане
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mingsoft · mcms18 февр. 2022 г.
- CVE-2021-4638640В плане
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to n
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mingsoft · mcms26 янв. 2022 г.
- CVE-2022-437540В плане
Mingsoft MCMS list sql injection
КритическаяCVSS 9,8Proof of conceptEPSS 3 %mingsoft · mcms9 дек. 2022 г.
- CVE-2022-2292940В плане
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbi
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mingsoft · mcms20 янв. 2022 г.
- CVE-2022-3050640В плане
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP fi
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mingsoft · mcms2 июн. 2022 г.
- CVE-2022-2292840В плане
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mingsoft · mcms20 янв. 2022 г.
- CVE-2023-5057840В плане
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %mingsoft · mcms30 дек. 2023 г.
- CVE-2021-4638440В плане
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mingsoft · mcms4 мар. 2022 г.
- CVE-2022-2331540В плане
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mingsoft · mcms20 янв. 2022 г.
- CVE-2022-2746639Наблюдать
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mingsoft · mcms2 мая 2022 г.
- CVE-2022-2331439Наблюдать
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mingsoft · mcms20 янв. 2022 г.
- CVE-2022-3194339Наблюдать
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mingsoft · mcms1 июл. 2022 г.
- CVE-2022-3004739Наблюдать
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms11 мая 2022 г.
- CVE-2022-3004839Наблюдать
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms11 мая 2022 г.
- CVE-2020-2091339Наблюдать
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms4 апр. 2023 г.
- CVE-2021-4486839Наблюдать
A problem was found in ming-soft MCMS v5.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms17 февр. 2022 г.
- CVE-2018-1883039Наблюдать
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms30 окт. 2018 г.
- CVE-2020-2326239Наблюдать
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms26 янв. 2021 г.
- CVE-2022-3627239Наблюдать
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms16 авг. 2022 г.
- CVE-2022-3659939Наблюдать
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mingsoft · mcms16 авг. 2022 г.