Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpmywind phpmywind 5.6 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPMyWind 5.6 which allows malicious users to create a new administrator account without authentication.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2020-18885
Command Injection in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
Phpmywind Phpmywind 5.6
NA
CVE-2020-21060
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote malicious user to gain privileges via the delete function of the administrator management page.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2020-18886
Unrestricted File Upload in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the component 'admin/upload_file_do.php'.
Phpmywind Phpmywind 5.6
NA
CVE-2020-21400
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote malicious user to execute arbitrary code via the id variable in the modify function.
Phpmywind Phpmywind 5.6
4.3
CVSSv2
CVE-2019-16703
admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.
Phpmywind Phpmywind 5.6
3.5
CVSSv2
CVE-2019-16704
admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
Phpmywind Phpmywind 5.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
CVE-2006-4304
CVE-2023-26603
CVE-2024-28327
CVE-2023-50363
CVE-2024-21905
template injection
CVE-2024-3400
cross-site request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started