Mingsoft

Mcms

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.52%
  • Veröffentlicht 26.01.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:34:00

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a ...

Exploit
  • EPSS 3.11%
  • Veröffentlicht 26.01.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:34:01

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

Exploit
  • EPSS 1.56%
  • Veröffentlicht 26.01.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:34:00

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql i...

Exploit
  • EPSS 1.82%
  • Veröffentlicht 21.01.2022 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:48:23

MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

Exploit
  • EPSS 1.6%
  • Veröffentlicht 21.01.2022 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:48:23

MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

Exploit
  • EPSS 23.69%
  • Veröffentlicht 21.01.2022 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:47:37

A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

Exploit
  • EPSS 2.58%
  • Veröffentlicht 21.01.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:47:37

MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

Exploit
  • EPSS 2.5%
  • Veröffentlicht 21.01.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:47:37

MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

Exploit
  • EPSS 1.15%
  • Veröffentlicht 26.01.2021 18:15:42
  • Zuletzt bearbeitet 21.11.2024 05:13:41

An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

  • EPSS 1.54%
  • Veröffentlicht 30.10.2018 06:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:42

An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.