Show filters
38 Total Results
Displaying 11-20 of 38
Sort by:
Attacker Value
Unknown

CVE-2022-28443

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
Attacker Value
Unknown

CVE-2022-28440

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2020-21650

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.
Attacker Value
Unknown

CVE-2020-21649

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.
Attacker Value
Unknown

CVE-2020-21651

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.
Attacker Value
Unknown

CVE-2020-21653

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.
Attacker Value
Unknown

CVE-2020-21652

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.
Attacker Value
Unknown

CVE-2020-20781

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
Attacker Value
Unknown

CVE-2020-19157

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.
Attacker Value
Unknown

CVE-2021-25809

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.