Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpmywind vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-7660
An issue exists in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php.
Phpmywind Phpmywind
6.1
CVSSv3
CVE-2019-7661
An issue exists in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.
Phpmywind Phpmywind
6.1
CVSSv3
CVE-2019-7402
An issue exists in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.
Phpmywind Phpmywind 5.5
4.9
CVSSv3
CVE-2019-7403
An issue exists in PHPMyWind 5.5. It allows remote malicious users to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&tbname=../ URI.
Phpmywind Phpmywind 5.5
6.1
CVSSv3
CVE-2018-11487
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
Phpmywind Phpmywind 5.5
7.2
CVSSv3
CVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
Phpmywind Phpmywind 5.6
4.8
CVSSv3
CVE-2019-8435
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
Phpmywind Phpmywind 5.5
6.5
CVSSv3
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPMyWind 5.6 which allows malicious users to create a new administrator account without authentication.
Phpmywind Phpmywind 5.6
7.2
CVSSv3
CVE-2020-18885
Command Injection in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
Phpmywind Phpmywind 5.6
7.2
CVSSv3
CVE-2020-18886
Unrestricted File Upload in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the component 'admin/upload_file_do.php'.
Phpmywind Phpmywind 5.6
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2021-35000
CVE-2024-4439
unauthorized
CVE-2024-0042
CVE-2024-31848
CVE-2023-40694
cache poisoning
CVE-2024-23707
firmware
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »