CVE Browser

CVE-2020-21400 HIGH

SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.

CVSS 7.2 EPSS 1.13% Jun 20, 2023
CVE-2020-21060 HIGH

SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.

CVSS 8.8 EPSS 0.92% Apr 4, 2023
CVE-2020-19964 MEDIUM

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authenti…

CVSS 6.5 EPSS 0.52% Oct 14, 2021
CVE-2021-39503 HIGH

PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject p…

CVSS 7.2 EPSS 2.82% Sep 7, 2021
CVE-2020-18886 HIGH

Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

CVSS 7.2 EPSS 1.80% Aug 20, 2021
CVE-2020-18885 HIGH

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

CVSS 7.2 EPSS 3.57% Aug 20, 2021
CVE-2020-18229 MEDIUM

Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_copyright" of comp…

CVSS 4.8 EPSS 0.93% May 27, 2021
CVE-2020-18230 MEDIUM

Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of com…

CVSS 4.8 EPSS 0.98% May 27, 2021
CVE-2019-16704 MEDIUM

admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.

CVSS 4.8 EPSS 0.65% Sep 23, 2019
CVE-2019-16703 MEDIUM

admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.

CVSS 6.1 EPSS 0.83% Sep 23, 2019
CVE-2019-7661 MEDIUM

An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.

CVSS 6.1 EPSS 0.87% Mar 7, 2019
CVE-2019-7660 MEDIUM

An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demon…

CVSS 6.1 EPSS 0.87% Mar 7, 2019
CVE-2019-8435 MEDIUM

admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

CVSS 4.8 EPSS 0.59% Feb 18, 2019
CVE-2019-7403 MEDIUM

An issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&t…

CVSS 4.9 EPSS 1.70% Feb 5, 2019
CVE-2019-7402 MEDIUM

An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg&#95;qqcode parameter. This can be exploited via C…

CVSS 6.1 EPSS 0.44% Feb 5, 2019
CVE-2018-17134 HIGH

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.

CVSS 7.2 EPSS 2.11% Sep 17, 2018
CVE-2018-17133 HIGH

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.

CVSS 7.2 EPSS 2.11% Sep 17, 2018
CVE-2018-17132 HIGH

admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.

CVSS 7.2 EPSS 2.11% Sep 17, 2018
CVE-2018-17131 HIGH

admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.

CVSS 7.2 EPSS 2.11% Sep 17, 2018
CVE-2018-17130 MEDIUM

PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,

CVSS 5.4 EPSS 0.64% Sep 17, 2018
CVE-2018-11487 MEDIUM

PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.

CVSS 6.1 EPSS 0.79% May 26, 2018
CVE-2017-12984 MEDIUM

PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.

CVSS 6.1 EPSS 2.24% Aug 21, 2017

Showing 1 to 22 CVEs · page 1