Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25997 | Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component. Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component. NVD description · AI analysis pending | 7.5 group max | 1% | PoC |
| — | |
| CVE-2021-33949 | An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function. An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-42897 | A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2020-18106 | The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection. The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2020-18544 | SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php". SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php". NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — |