mccms(漫城CMS)是中国烟雨江南(chshcms)个人开发者的一个快速建站系统。 mccms 2.6版本存在SQL注入漏洞,该漏洞源于允许攻击者通过文件copyright/46/finish/1/list/1存在SQL注入漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | mccms | 2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-5016 | 6.3 MEDIUM | spider-flow API DataSourceController.java DriverManager.getConnection deserialization |
| CVE-2023-5022 | 5.5 MEDIUM | DedeCMS select_templets_post.php absolute path traversal |
| CVE-2023-5017 | 5.5 MEDIUM | lmxcms admin.php sql injection |
| CVE-2023-5025 | 3.5 LOW | KOHA MARC search.pl cross site scripting |
| CVE-2023-5024 | 3.5 LOW | Planno Comment cross site scripting |
| CVE-2023-5015 | 3.5 LOW | UCMS cross site scripting |
No comments yet