Sun.Net

Wmpro

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 29.12.2025 06:39:27
  • Zuletzt bearbeitet 31.12.2025 20:53:21

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • EPSS 0.1%
  • Veröffentlicht 29.12.2025 06:31:49
  • Zuletzt bearbeitet 31.12.2025 20:55:14

WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.

  • EPSS 0.07%
  • Veröffentlicht 18.09.2023 03:15:08
  • Zuletzt bearbeitet 21.11.2024 08:08:49

SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.

  • EPSS 0.23%
  • Veröffentlicht 18.09.2023 03:15:07
  • Zuletzt bearbeitet 21.11.2024 08:08:49

SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege or a privileged account can exploit this vulnerability to inject and execute arbitrary system...

Exploit
  • EPSS 5.57%
  • Veröffentlicht 11.07.2019 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:20:27

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.