48 results (0.010 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

17 Sep 2023 — A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871. • https://github.com/1541284314/cve/blob/main/README.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

14 Jun 2023 — A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/HuBenLab/HuBenVulList/blob/main/MCCMS%20is%20vulnerable%20to%20Server-side%20request%20forgery%20(SSRF)%202.md • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

14 Jun 2023 — A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. • https://github.com/HuBenLab/HuBenVulList/blob/main/MCCMS%20is%20vulnerable%20to%20Server-side%20request%20forgery%20(SSRF)%201.md • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

28 Apr 2023 — mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). • https://github.com/chshcms/mccms/issues/3 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

28 Apr 2023 — SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. • https://github.com/chshcms/mccms/issues/1 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 1

28 Apr 2023 — An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. • https://github.com/chshcms/mccms/issues/2 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

09 Jun 2022 — A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. Una vulnerabilidad de tipo Cross-site request forgery (CSRF) en Cscms music portal system versión v4.2, permite a atacantes remotos cambiar el nombre de usuario y la contraseña del administrador • https://github.com/chshcms/cscms/issues/37 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

26 May 2022 — CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del. Se ha detectado que CSCMS Music Portal System versión v4.2, contiene una vulnerabilidad de inyección SQL ciega por medio del parámetro id en /admin.php/singer/admin/singer/del • https://github.com/chshcms/cscms/issues/28#issue-1209044410 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

26 May 2022 — CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy. Se ha detectado que CSCMS Music Portal System versión v4.2, contiene una vulnerabilidad de inyección SQL ciega por medio del parámetro id en /admin.php/singer/admin/singer/hy • https://github.com/chshcms/cscms/issues/27#issue-1209040138 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

26 May 2022 — CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. Se ha detectado que CSCMS Music Portal System versión v4.2, contiene una vulnerabilidad de inyección SQL ciega por medio del parámetro id en /admin.php/user/level_del • https://github.com/chshcms/cscms/issues/30#issue-1209049714 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •