Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpmywind phpmywind 5.6 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2020-21400
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote malicious user to execute arbitrary code via the id variable in the modify function.
Phpmywind Phpmywind 5.6
NA
CVE-2020-21060
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote malicious user to gain privileges via the delete function of the administrator management page.
Phpmywind Phpmywind 5.6
4.3
CVSSv2
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPMyWind 5.6 which allows malicious users to create a new administrator account without authentication.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2020-18885
Command Injection in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2020-18886
Unrestricted File Upload in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the component 'admin/upload_file_do.php'.
Phpmywind Phpmywind 5.6
4.3
CVSSv2
CVE-2019-16703
admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.
Phpmywind Phpmywind 5.6
3.5
CVSSv2
CVE-2019-16704
admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.
Phpmywind Phpmywind 5.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-26978
CVE-2024-26982
wireless
CVE-2023-6949
CVE-2024-26980
CVE-2024-32766
CVE-2024-26939
cache poisoning
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started