An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
6.5CVSS
6.5AI Score
0.001EPSS
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.
8.8CVSS
8.6AI Score
0.001EPSS
6.1CVSS
5.9AI Score
0.001EPSS
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
9.8CVSS
9.3AI Score
0.008EPSS
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
8.8CVSS
8.6AI Score
0.001EPSS
CScms 4.1 allows arbitrary directory deletion via a dir=..\ substring to plugins\sys\admin\Plugins.php.
7.5CVSS
7.4AI Score
0.002EPSS
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
9.8CVSS
9.5AI Score
0.05EPSS
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
8.1CVSS
8AI Score
0.001EPSS
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
6.5CVSS
6.4AI Score
0.001EPSS
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
9.8CVSS
9.3AI Score
0.003EPSS
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.
9.8CVSS
9.8AI Score
0.008EPSS
9.8CVSS
9.9AI Score
0.002EPSS
9.8CVSS
9.9AI Score
0.002EPSS
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
5.4CVSS
5.5AI Score
0.001EPSS
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
7.2CVSS
7.2AI Score
0.001EPSS
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
7.2CVSS
7.3AI Score
0.001EPSS
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
7.2CVSS
7.2AI Score
0.001EPSS
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
7.2CVSS
7.2AI Score
0.001EPSS
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.
7.2CVSS
7.2AI Score
0.001EPSS
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
8.8CVSS
9AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
9.8CVSS
9.7AI Score
0.002EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.
8.8CVSS
8.9AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.
8.8CVSS
8.9AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.
8.8CVSS
8.9AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.
8.8CVSS
8.9AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.
7.2CVSS
7.2AI Score
0.001EPSS
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.
7.2CVSS
7.2AI Score
0.001EPSS
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
6.5CVSS
6.6AI Score
0.001EPSS
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
9.8CVSS
9.7AI Score
0.001EPSS
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
6.5CVSS
6.4AI Score
0.001EPSS
8.8CVSS
8.6AI Score
0.001EPSS
A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit...
8.8CVSS
8.6AI Score
0.001EPSS
A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has...
8.8CVSS
8.7AI Score
0.001EPSS
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associ...
8.8CVSS
8.9AI Score
0.001EPSS