Vulnerabilities
22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-21400 | SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function. SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2020-21060 | SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page. SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-19964 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentic A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2021-39503 | PHPMyWind 5.6 is vulnerable to Remote Code Execution. PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without " , ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file. NVD description · AI analysis pending | 7.2 | 3% | PoC ×2 |
| — | |
| CVE-2020-18885 +1 in the same advisory: …18886 | Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'. Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'. NVD description · AI analysis pending | 7.2 | 4% | PoC |
| — | |
| CVE-2020-18230 +1 in the same advisory: …18229 | Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of comp Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of component " /admin/web_config.php". NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2019-16703 +1 in the same advisory: …16704 | admin/infolist_add.php in PHPMyWind 5.6 has stored XSS. admin/infolist_add.php in PHPMyWind 5.6 has stored XSS. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2019-7661 +1 in the same advisory: …7660 | An issue was discovered in PHPMyWind 5.5. An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-8435 | admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2019-7402 +1 in the same advisory: …7403 | An issue was discovered in PHPMyWind 5.5. An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2018-17134 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field. admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field. NVD description · AI analysis pending | 7.2 group max | 2% | PoC |
| — | |
| CVE-2018-11487 | PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2017-12984 | PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php. NVD description · AI analysis pending | 6.1 | 2% |
| — |