net.mingsoft:ms-mcms@5.4.2 vulnerabilities
-
latest version
5.4.2
-
first published
7 years ago
-
latest version published
2 months ago
-
licenses detected
- [5.2.0.RELEASE,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the net.mingsoft:ms-mcms package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection') due to the front-end file upload process. An attacker can execute arbitrary commands on the server by uploading a malicious file. How to fix Improper Control of Generation of Code ('Code Injection')? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type via a crafted POST request to How to fix Unrestricted Upload of File with Dangerous Type? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Information Exposure via a crafted script to the How to fix Information Exposure? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to SQL Injection via the How to fix SQL Injection? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) allowing an attacker to add an administrator account via How to fix Cross-site Request Forgery (CSRF)? There is no fixed version for |
[4.6.5,)
|
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) where it's possible to add an administrator account via How to fix Cross-site Request Forgery (CSRF)? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via How to fix Cross-site Request Forgery (CSRF)? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to SQL Injection via the How to fix SQL Injection? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to SQL Injection via How to fix SQL Injection? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to External Control of File Name or Path via the How to fix External Control of File Name or Path? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Server-side Template Injection (SSTI) via the Template Management module, where it is possible to add a template with a crafted payload in order to execute commands on the underlaying server. How to fix Server-side Template Injection (SSTI)? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Arbitrary File Upload via the ##PoC
How to fix Arbitrary File Upload? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Arbitrary File Deletion via the How to fix Arbitrary File Deletion? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to SQL Injection due to improper input sanitization in How to fix SQL Injection? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Arbitrary File Upload via the How to fix Arbitrary File Upload? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to SQL Injection via the IDictBiz interface, through which the value of How to fix SQL Injection? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to SQL Injection via the IModelDataBiz interface, which requires implementing the How to fix SQL Injection? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Arbitrary Code Execution which have a hardcoded How to fix Arbitrary Code Execution? There is no fixed version for |
[5.2.4,)
|
Affected versions of this package are vulnerable to Arbitrary File Upload via the How to fix Arbitrary File Upload? There is no fixed version for |
[0,)
|
Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? There is no fixed version for |
[0,)
|