← Back

Wms Project

wms_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Wms
wms

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wms Project
1Wms
Mar 18, 2025
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
1Wms Project
1Wms
Nov 21, 2024
Aug 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
1Wms Project
1Wms
Nov 21, 2024
Jul 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".