Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Phpmywind HIGH 7.2
CVE-2020-21400

SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify functi…

No fix yet
Fix from $1,950 2023-06-20
Phpmywind HIGH 8.8
CVE-2020-21060

SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator managem…

No fix yet
Fix from $1,950 2023-04-04
Phpmywind MEDIUM 6.5
CVE-2020-19964

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account withou…

No fix yet
Fix from $1,600 2021-10-14
Phpmywind HIGH 7.2
CVE-2021-39503

PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker ca…

No fix yet
Fix from $1,950 2021-09-07
Phpmywind HIGH 7.2
CVE-2020-18885

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.…

No fix yet
Fix from $1,950 2021-08-20
Phpmywind HIGH 7.2
CVE-2020-18886

Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

No fix yet
Fix from $1,950 2021-08-20
Phpmywind MEDIUM 6.1
CVE-2019-16703

admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.

No fix yet
Fix from $1,600 2019-09-23
Phpmywind MEDIUM 6.1
CVE-2019-7402

An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg&#95;qqcode parameter. This can be explo…

No fix yet
Fix from $1,600 2019-02-05
Phpmywind HIGH 7.2
CVE-2018-17131

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.

No fix yet
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17132

admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.

No fix yet
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17133

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.

No fix yet
Fix from $1,950 2018-09-17
Phpmywind HIGH 7.2
CVE-2018-17134

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath…

No fix yet
Fix from $1,950 2018-09-17
Phpmywind MEDIUM 5.4
CVE-2018-17130

PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,

No fix yet
Fix from $1,600 2018-09-17
Phpmywind MEDIUM 6.1
CVE-2018-11487

PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.

Mitigation only
Fix from $1,600 2018-05-26
Phpmywind MEDIUM 6.1
CVE-2017-12984

PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.

No fix yet
Fix from $1,600 2017-08-21