Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2020-21400 SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify functi… Phpmywind No fix yet Fix from $1,9502023-06-20 HIGH 8.8 CVE-2020-21060 SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator managem… Phpmywind No fix yet Fix from $1,9502023-04-04 MEDIUM 6.5 CVE-2020-19964 A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account withou… Phpmywind No fix yet Fix from $1,6002021-10-14 HIGH 7.2 CVE-2021-39503 PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker ca… Phpmywind No fix yet Fix from $1,9502021-09-07 HIGH 7.2 CVE-2020-18885 Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.… Phpmywind No fix yet Fix from $1,9502021-08-20 HIGH 7.2 CVE-2020-18886 Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'. Phpmywind No fix yet Fix from $1,9502021-08-20 MEDIUM 6.1 CVE-2019-16703 admin/infolist_add.php in PHPMyWind 5.6 has stored XSS. Phpmywind No fix yet Fix from $1,6002019-09-23 MEDIUM 6.1 CVE-2019-7660 An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability… Phpmywind after 5.5 Fix from $1,6002019-03-07 MEDIUM 6.1 CVE-2019-7661 An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vuln… Phpmywind after 5.5 Fix from $1,6002019-03-07 MEDIUM 6.1 CVE-2019-7402 An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg&#95;qqcode parameter. This can be explo… Phpmywind No fix yet Fix from $1,6002019-02-05 HIGH 7.2 CVE-2018-17131 admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. Phpmywind No fix yet Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17132 admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. Phpmywind No fix yet Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17133 admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. Phpmywind No fix yet Fix from $1,9502018-09-17 HIGH 7.2 CVE-2018-17134 admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath… Phpmywind No fix yet Fix from $1,9502018-09-17 MEDIUM 5.4 CVE-2018-17130 PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, Phpmywind No fix yet Fix from $1,6002018-09-17 MEDIUM 6.1 CVE-2018-11487 PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. Phpmywind Mitigation only Fix from $1,6002018-05-26 MEDIUM 6.1 CVE-2017-12984 PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. Phpmywind No fix yet Fix from $1,6002017-08-21