lmxcms(梦想cms)是中国梦想cms(lmxcms)公司的一个建站系统。 lmxcms 1.41之前版本存在SQL注入漏洞,该漏洞源于文件 admin.php 存在未知功能,通过参数lid 导致sql 注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | lmxcms | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-5016 | 6.3 MEDIUM | spider-flow API DataSourceController.java DriverManager.getConnection deserialization |
| CVE-2023-5029 | 5.5 MEDIUM | mccms 1 sql injection |
| CVE-2023-5022 | 5.5 MEDIUM | DedeCMS select_templets_post.php absolute path traversal |
| CVE-2023-5025 | 3.5 LOW | KOHA MARC search.pl cross site scripting |
| CVE-2023-5024 | 3.5 LOW | Planno Comment cross site scripting |
| CVE-2023-5015 | 3.5 LOW | UCMS cross site scripting |
No comments yet