Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2022-28552

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
Attacker Value
Unknown

CVE-2020-28103

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
cscms v4.1 allows for SQL injection via the "page_del" function.
Attacker Value
Unknown

CVE-2020-28102

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
cscms v4.1 allows for SQL injection via the "js_del" function.
Attacker Value
Unknown

CVE-2020-22848

Disclosure Date: August 30, 2021 (last updated November 29, 2024)
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.
Attacker Value
Unknown

CVE-2019-9598

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
0
Attacker Value
Unknown

CVE-2019-6779

Disclosure Date: January 24, 2019 (last updated November 27, 2024)
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
0
Attacker Value
Unknown

CVE-2018-17126

Disclosure Date: September 17, 2018 (last updated November 27, 2024)
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
0
Attacker Value
Unknown

CVE-2018-17125

Disclosure Date: September 17, 2018 (last updated November 27, 2024)
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
0
Attacker Value
Unknown

CVE-2018-16731

Disclosure Date: September 08, 2018 (last updated November 27, 2024)
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
0
Attacker Value
Unknown

CVE-2018-16730

Disclosure Date: September 08, 2018 (last updated November 27, 2024)
\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.
0