Show filters
40 Total Results
Displaying 21-30 of 40
Sort by:
Attacker Value
Unknown

CVE-2021-46384

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.
Attacker Value
Unknown

CVE-2022-25125

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
Attacker Value
Unknown

CVE-2022-23899

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
Attacker Value
Unknown

CVE-2022-23898

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
Attacker Value
Unknown

CVE-2021-46063

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
Attacker Value
Unknown

CVE-2021-46062

Disclosure Date: February 18, 2022 (last updated October 07, 2023)
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
Attacker Value
Unknown

CVE-2021-46037

Disclosure Date: February 18, 2022 (last updated October 07, 2023)
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
Attacker Value
Unknown

CVE-2021-46036

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-44868

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
Attacker Value
Unknown

CVE-2021-46385

Disclosure Date: January 26, 2022 (last updated February 23, 2025)
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.