Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpmywind phpmywind vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-7661
An issue exists in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.
Phpmywind Phpmywind
6.1
CVSSv3
CVE-2019-7660
An issue exists in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php.
Phpmywind Phpmywind
8.8
CVSSv3
CVE-2020-21060
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote malicious user to gain privileges via the delete function of the administrator management page.
Phpmywind Phpmywind 5.6
7.2
CVSSv3
CVE-2020-21400
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote malicious user to execute arbitrary code via the id variable in the modify function.
Phpmywind Phpmywind 5.6
6.1
CVSSv3
CVE-2017-12984
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
Phpmywind Phpmywind 5.3
1 EDB exploit
6.1
CVSSv3
CVE-2018-11487
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
Phpmywind Phpmywind 5.5
4.8
CVSSv3
CVE-2020-18229
Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote malicious users to execute arbitrary code by injecting scripts into the parameter "$cfg_copyright" of component " /admin/web_config.php".
Phpmywind Phpmywind 5.5
6.5
CVSSv3
CVE-2020-19964
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPMyWind 5.6 which allows malicious users to create a new administrator account without authentication.
Phpmywind Phpmywind 5.6
6.1
CVSSv3
CVE-2019-7402
An issue exists in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.
Phpmywind Phpmywind 5.5
4.9
CVSSv3
CVE-2019-7403
An issue exists in PHPMyWind 5.5. It allows remote malicious users to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&tbname=../ URI.
Phpmywind Phpmywind 5.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21991
CVE-2024-32674
path traversal
CVE-2023-21987
denial of service
dos
CVE-2024-4647
CVE-2024-25519
CVE-2024-33612
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »