Chshcms
chshcms
53 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (53)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands |
MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function,...Show more |
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request. |
A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/controllers/admin/Backups.php. The manipulation of the argument...Show more |
A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php. The manipulation of the argument pic leads to server-side r...Show more |
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql inje...Show more |
A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side r...Show more |
A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads t...Show more |
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. |
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. |
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). |
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del. |
1Chshcms 1Cscms Music Portal System Nov 21, 2024 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del. |