native-php-cms是FLi个人开发者的一个建站系统。 native-php-cms 1.0版本存在安全漏洞,该漏洞源于Backend组件中文件/fladmin/sysconfig_doedit.php存在授权不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fanli2012 | native-php-cms | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-0486 | 7.3 HIGH | Fanli2012 native-php-cms login.php sql injection |
| CVE-2025-0482 | 7.3 HIGH | Fanli2012 native-php-cms user_recoverpwd.php default credentials |
| CVE-2025-0488 | 6.3 MEDIUM | Fanli2012 native-php-cms product_list.php sql injection |
| CVE-2025-0491 | 6.3 MEDIUM | Fanli2012 native-php-cms cat_dodel.php sql injection |
| CVE-2025-0490 | 6.3 MEDIUM | Fanli2012 native-php-cms article_dodel.php sql injection |
| CVE-2025-0489 | 6.3 MEDIUM | Fanli2012 native-php-cms friendlink_dodel.php sql injection |
| CVE-2025-0487 | 6.3 MEDIUM | Fanli2012 native-php-cms cat_edit.php sql injection |
| CVE-2025-0483 | 3.5 LOW | Fanli2012 native-php-cms jump.php cross site scripting |
| CVE-2025-0485 | 3.5 LOW | Fanli2012 native-php-cms sysconfig_doedit.php cross site scripting |
No comments yet