
CVE-2020-20636
https://notcve.org/view.php?id=CVE-2020-20636
20 Jun 2023 — SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function. • https://github.com/joyplus/joyplus-cms/issues/447 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2020-22124
https://notcve.org/view.php?id=CVE-2020-22124
18 Aug 2021 — A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. Una vulnerabilidad en el componente \inc\config.php de joyplus-cms versión v1.6, permite a atacantes acceder a información confidencial. • https://github.com/876054426/vul/issues/1 • CWE-552: Files or Directories Accessible to External Parties •

CVE-2019-17175
https://notcve.org/view.php?id=CVE-2019-17175
04 Oct 2019 — joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. joyplus-cms versión 1.6.0, permite un salto de ruta absoluto de manager/admin_pic.php?rootpath=. • https://github.com/joyplus/joyplus-cms/issues/443 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2018-14500
https://notcve.org/view.php?id=CVE-2018-14500
22 Jul 2018 — joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en manager/collect/collect_vod_zhuiju.php mediante el parámetro keyword. • https://github.com/joyplus/joyplus-cms/issues/431 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-14388
https://notcve.org/view.php?id=CVE-2018-14388
18 Jul 2018 — joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en manager/admin_ajax.php mediante el parámetro del array can_search_device. • https://github.com/joyplus/joyplus-cms/issues/429 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-14389
https://notcve.org/view.php?id=CVE-2018-14389
18 Jul 2018 — joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. joyplus-cms 1.6.0 tiene una inyección SQL en manager/admin_ajax.php mediante el parámetro val. • https://github.com/joyplus/joyplus-cms/issues/430 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2018-14334
https://notcve.org/view.php?id=CVE-2018-14334
17 Jul 2018 — manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alter the flow of control. Consequently, one can upload and execute a .php file, a similar issue to CVE-2018-8766. manager/editor/upload.php en joyplus-cms 1.6.0 permite la subida de archivos arbitrarios debido a que una detección de una extensión de archivo prohibida simplemente establece el valor $errm y no altera el flujo de contr... • https://github.com/joyplus/joyplus-cms/issues/428 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2018-12905
https://notcve.org/view.php?id=CVE-2018-12905
27 Jun 2018 — joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) en admin_player.php, relacionado con las acciones "system manage" y "add" en manager/index.php. • https://github.com/joyplus/joyplus-cms/issues/427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-12039
https://notcve.org/view.php?id=CVE-2018-12039
07 Jun 2018 — joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring. joyplus-cms 1.6.0 permite la ejecución remota de código debido a un problema de ejecución de comandos SQL arbitrarios en manager/index.php relacionados con el uso de una subcadena "/!select/" en lugar de una subcadena select. • https://github.com/joyplus/joyplus-cms/issues/425 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2018-10096
https://notcve.org/view.php?id=CVE-2018-10096
13 Apr 2018 — joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. joyplus-cms 1.6.0 tiene Cross-Site Scripting (XSS) mediante el parámetro device_name en una petición manager/admin_ajax.php?action=save flag=add. • https://github.com/joyplus/joyplus-cms/issues/424 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •