İçeriğe atla
Noroxi

phpmywind kayıtları

phpmywind üreticisine ait 22 yayımlanmış kayıt.

Tüm kayıtlar

22 kayıt
  • CVE-2020-21060
    35İzleyin

    SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrato

    YüksekCVSS 8,8İstismar yokEPSS %1

    phpmywind · phpmywind4 Nis 2023

  • CVE-2020-18885
    29İzleyin

    Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/we

    YüksekCVSS 7,2İstismar yokEPSS %4

    phpmywind · phpmywind20 Ağu 2021

  • CVE-2021-39503
    29İzleyin

    PHPMyWind 5.6 is vulnerable to Remote Code Execution.

    YüksekCVSS 7,2İstismar yokEPSS %3

    phpmywind · phpmywind7 Eyl 2021

  • CVE-2018-17134
    29İzleyin

    admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cf

    YüksekCVSS 7,2İstismar yokEPSS %2

    phpmywind · phpmywind17 Eyl 2018

  • CVE-2018-17133
    29İzleyin

    admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.

    YüksekCVSS 7,2İstismar yokEPSS %2

    phpmywind · phpmywind17 Eyl 2018

  • CVE-2018-17131
    29İzleyin

    admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.

    YüksekCVSS 7,2İstismar yokEPSS %2

    phpmywind · phpmywind17 Eyl 2018

  • CVE-2018-17132
    29İzleyin

    admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.

    YüksekCVSS 7,2İstismar yokEPSS %2

    phpmywind · phpmywind17 Eyl 2018

  • CVE-2020-18886
    29İzleyin

    Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

    YüksekCVSS 7,2İstismar yokEPSS %2

    phpmywind · phpmywind20 Ağu 2021

  • CVE-2020-21400
    28İzleyin

    SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modi

    YüksekCVSS 7,2İstismar yokEPSS %1

    phpmywind · phpmywind20 Haz 2023

  • CVE-2020-19964
    26İzleyin

    A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator accou

    OrtaCVSS 6,5İstismar yokEPSS %1

    phpmywind · phpmywind14 Eki 2021

  • CVE-2017-12984
    25İzleyin

    PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    phpmywind · phpmywind21 Ağu 2017

  • CVE-2019-7661
    24İzleyin

    An issue was discovered in PHPMyWind 5.5.

    OrtaCVSS 6,1İstismar yokEPSS %1

    phpmywind · phpmywind7 Mar 2019

  • CVE-2019-7660
    24İzleyin

    An issue was discovered in PHPMyWind 5.5.

    OrtaCVSS 6,1İstismar yokEPSS %1

    phpmywind · phpmywind7 Mar 2019

  • CVE-2019-16703
    24İzleyin

    admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    phpmywind · phpmywind23 Eyl 2019

  • CVE-2018-11487
    24İzleyin

    PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    phpmywind · phpmywind26 May 2018

  • CVE-2019-7402
    24İzleyin

    An issue was discovered in PHPMyWind 5.5.

    OrtaCVSS 6,1İstismar yokEPSS %0

    phpmywind · phpmywind5 Şub 2019

  • CVE-2018-17130
    21İzleyin

    PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,

    OrtaCVSS 5,4İstismar yokEPSS %1

    phpmywind · phpmywind17 Eyl 2018

  • CVE-2019-7403
    20İzleyin

    An issue was discovered in PHPMyWind 5.5.

    OrtaCVSS 4,9İstismar yokEPSS %2

    phpmywind · phpmywind5 Şub 2019

  • CVE-2020-18230
    19İzleyin

    Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg

    OrtaCVSS 4,8İstismar yokEPSS %1

    phpmywind · phpmywind27 May 2021

  • CVE-2020-18229
    19İzleyin

    Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg

    OrtaCVSS 4,8İstismar yokEPSS %1

    phpmywind · phpmywind27 May 2021

  • CVE-2019-16704
    19İzleyin

    admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.

    OrtaCVSS 4,8İstismar yokEPSS %1

    phpmywind · phpmywind23 Eyl 2019

  • CVE-2019-8435
    19İzleyin

    admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

    OrtaCVSS 4,8İstismar yokEPSS %1

    phpmywind · phpmywind17 Şub 2019