MingSoft kayıtları
mingsoft üreticisine ait 48 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 16
- Düzeltme kaydı olan
- %22,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-434 Unrestricted Upload of File with Dangerous Type12
- CWE-707 Improper Neutralization3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
48 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2022-22930İstismar yok | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code vimingsoft · mcms | Kritik9,8 | — | %23,7 | 20 Oca 2022 |
41Planlayın | CVE-2022-23898Kavram kanıtı | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %7,7 | 3 Mar 2022 |
41Planlayın | CVE-2022-25125Kavram kanıtı | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %7,0 | 3 Mar 2022 |
41Planlayın | CVE-2022-26585Kavram kanıtı | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %5,5 | 4 Nis 2022 |
40Planlayın | CVE-2024-22567İstismar yok | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.mingsoft · mcms · CWE-434 | Yüksek8,8 | — | %17,8 | 5 Şub 2024 |
40Planlayın | CVE-2021-46036İstismar yok | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary codemingsoft · mcms · CWE-434 | Kritik9,8 | — | %3,7 | 18 Şub 2022 |
40Planlayın | CVE-2021-46386İstismar yok | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to nmingsoft · mcms · CWE-434 | Kritik9,8 | — | %3,1 | 26 Oca 2022 |
40Planlayın | CVE-2022-4375Kavram kanıtı | Mingsoft MCMS list sql injectionmingsoft · mcms · CWE-707 | Kritik9,8 | — | %3,0 | 9 Ara 2022 |
40Planlayın | CVE-2022-22929İstismar yok | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbimingsoft · mcms · CWE-434 | Kritik9,8 | — | %2,6 | 20 Oca 2022 |
40Planlayın | CVE-2022-30506İstismar yok | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP fimingsoft · mcms · CWE-434 | Kritik9,8 | — | %2,6 | 2 Haz 2022 |
40Planlayın | CVE-2022-22928İstismar yok | MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.mingsoft · mcms · CWE-798 | Kritik9,8 | — | %2,5 | 20 Oca 2022 |
40Planlayın | CVE-2023-50578Kavram kanıtı | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %2,2 | 30 Ara 2023 |
40Planlayın | CVE-2021-46384İstismar yok | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.mingsoft · mcms · CWE-306 | Kritik9,8 | — | %2,2 | 4 Mar 2022 |
40Planlayın | CVE-2022-23315İstismar yok | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.mingsoft · mcms · CWE-434 | Kritik9,8 | — | %1,8 | 20 Oca 2022 |
39İzleyin | CVE-2022-27466İstismar yok | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,6 | 2 May 2022 |
39İzleyin | CVE-2022-23314İstismar yok | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,6 | 20 Oca 2022 |
39İzleyin | CVE-2022-31943İstismar yok | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.mingsoft · mcms · CWE-434 | Kritik9,8 | — | %1,5 | 1 Tem 2022 |
39İzleyin | CVE-2022-30047İstismar yok | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,4 | 11 May 2022 |
39İzleyin | CVE-2022-30048İstismar yok | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,4 | 11 May 2022 |
39İzleyin | CVE-2020-20913İstismar yok | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,4 | 4 Nis 2023 |
39İzleyin | CVE-2021-44868İstismar yok | A problem was found in ming-soft MCMS v5.1.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,4 | 17 Şub 2022 |
39İzleyin | CVE-2018-18830İstismar yok | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.mingsoft · mcms · CWE-434 | Kritik9,8 | — | %1,2 | 30 Eki 2018 |
39İzleyin | CVE-2020-23262İstismar yok | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,1 | 26 Oca 2021 |
39İzleyin | CVE-2022-36272İstismar yok | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,1 | 16 Ağu 2022 |
39İzleyin | CVE-2022-36599İstismar yok | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.mingsoft · mcms · CWE-89 | Kritik9,8 | — | %1,1 | 16 Ağu 2022 |
- CVE-2022-2293046Planlayın
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code vi
KritikCVSS 9,8İstismar yokEPSS %24mingsoft · mcms20 Oca 2022
- CVE-2022-2389841Planlayın
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
KritikCVSS 9,8Kavram kanıtıEPSS %8mingsoft · mcms3 Mar 2022
- CVE-2022-2512541Planlayın
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
KritikCVSS 9,8Kavram kanıtıEPSS %7mingsoft · mcms3 Mar 2022
- CVE-2022-2658541Planlayın
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
KritikCVSS 9,8Kavram kanıtıEPSS %5mingsoft · mcms4 Nis 2022
- CVE-2024-2256740Planlayın
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
YüksekCVSS 8,8İstismar yokEPSS %18mingsoft · mcms5 Şub 2024
- CVE-2021-4603640Planlayın
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code
KritikCVSS 9,8İstismar yokEPSS %4mingsoft · mcms18 Şub 2022
- CVE-2021-4638640Planlayın
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to n
KritikCVSS 9,8İstismar yokEPSS %3mingsoft · mcms26 Oca 2022
- CVE-2022-437540Planlayın
Mingsoft MCMS list sql injection
KritikCVSS 9,8Kavram kanıtıEPSS %3mingsoft · mcms9 Ara 2022
- CVE-2022-2292940Planlayın
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbi
KritikCVSS 9,8İstismar yokEPSS %3mingsoft · mcms20 Oca 2022
- CVE-2022-3050640Planlayın
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP fi
KritikCVSS 9,8İstismar yokEPSS %3mingsoft · mcms2 Haz 2022
- CVE-2022-2292840Planlayın
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
KritikCVSS 9,8İstismar yokEPSS %3mingsoft · mcms20 Oca 2022
- CVE-2023-5057840Planlayın
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
KritikCVSS 9,8Kavram kanıtıEPSS %2mingsoft · mcms30 Ara 2023
- CVE-2021-4638440Planlayın
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.
KritikCVSS 9,8İstismar yokEPSS %2mingsoft · mcms4 Mar 2022
- CVE-2022-2331540Planlayın
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
KritikCVSS 9,8İstismar yokEPSS %2mingsoft · mcms20 Oca 2022
- CVE-2022-2746639İzleyin
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
KritikCVSS 9,8İstismar yokEPSS %2mingsoft · mcms2 May 2022
- CVE-2022-2331439İzleyin
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
KritikCVSS 9,8İstismar yokEPSS %2mingsoft · mcms20 Oca 2022
- CVE-2022-3194339İzleyin
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2mingsoft · mcms1 Tem 2022
- CVE-2022-3004739İzleyin
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms11 May 2022
- CVE-2022-3004839İzleyin
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms11 May 2022
- CVE-2020-2091339İzleyin
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms4 Nis 2023
- CVE-2021-4486839İzleyin
A problem was found in ming-soft MCMS v5.1.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms17 Şub 2022
- CVE-2018-1883039İzleyin
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms30 Eki 2018
- CVE-2020-2326239İzleyin
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms26 Oca 2021
- CVE-2022-3627239İzleyin
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms16 Ağu 2022
- CVE-2022-3659939İzleyin
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
KritikCVSS 9,8İstismar yokEPSS %1mingsoft · mcms16 Ağu 2022