Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpmywind phpmywind vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2020-18229
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote malicious users to execute arbitrary code by injecting scripts into the parameter "$cfg_copyright" of component " /admin/web_config.php".
Phpmywind Phpmywind 5.5
3.5
CVSSv2
CVE-2020-18230
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote malicious users to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of component " /admin/web_config.php".
Phpmywind Phpmywind 5.5
3.5
CVSSv2
CVE-2018-17130
PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
Phpmywind Phpmywind 5.5
6.5
CVSSv2
CVE-2018-17131
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
Phpmywind Phpmywind 5.5
6.5
CVSSv2
CVE-2018-17132
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
Phpmywind Phpmywind 5.5
6.5
CVSSv2
CVE-2020-18886
Unrestricted File Upload in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the component 'admin/upload_file_do.php'.
Phpmywind Phpmywind 5.6
4.3
CVSSv2
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPMyWind 5.6 which allows malicious users to create a new administrator account without authentication.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2020-18885
Command Injection in PHPMyWind v5.6 allows remote malicious users to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
Phpmywind Phpmywind 5.6
6.5
CVSSv2
CVE-2018-17134
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.
Phpmywind Phpmywind 5.5
6.5
CVSSv2
CVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
Phpmywind Phpmywind 5.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »