CVE-2023-5029 – mccms 1 sql injection
https://notcve.org/view.php?id=CVE-2023-5029
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871. • https://github.com/1541284314/cve/blob/main/README.md https://vuldb.com/?ctiid.239871 https://vuldb.com/?id.239871 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-3236 – mccms Comic.php pic_save server-side request forgery
https://notcve.org/view.php?id=CVE-2023-3236
A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/HuBenLab/HuBenVulList/blob/main/MCCMS%20is%20vulnerable%20to%20Server-side%20request%20forgery%20(SSRF)%202.md https://vuldb.com/?ctiid.231507 https://vuldb.com/?id.231507 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2023-3235 – mccms Comic.php pic_api server-side request forgery
https://notcve.org/view.php?id=CVE-2023-3235
A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. • https://github.com/HuBenLab/HuBenVulList/blob/main/MCCMS%20is%20vulnerable%20to%20Server-side%20request%20forgery%20(SSRF)%201.md https://vuldb.com/?ctiid.231506 https://vuldb.com/?id.231506 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2023-26781
https://notcve.org/view.php?id=CVE-2023-26781
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. • https://github.com/chshcms/mccms/issues/1 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •