Vulnerabilities (CVE)

Filtered by vendor Phpmywind Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18885 1 Phpmywind 1 Phpmywind 2022-07-10 6.5 MEDIUM 7.2 HIGH
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
CVE-2021-39503 1 Phpmywind 1 Phpmywind 2021-09-14 6.5 MEDIUM 7.2 HIGH
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
CVE-2020-18886 1 Phpmywind 1 Phpmywind 2021-08-24 6.5 MEDIUM 7.2 HIGH
Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.
CVE-2018-17131 1 Phpmywind 1 Phpmywind 2018-11-01 6.5 MEDIUM 7.2 HIGH
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
CVE-2018-17132 1 Phpmywind 1 Phpmywind 2018-11-01 6.5 MEDIUM 7.2 HIGH
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
CVE-2018-17133 1 Phpmywind 1 Phpmywind 2018-11-01 6.5 MEDIUM 7.2 HIGH
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
CVE-2018-17134 1 Phpmywind 1 Phpmywind 2018-11-01 6.5 MEDIUM 7.2 HIGH
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.