Product:

Hongcms

(Hongcms_project)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 20
Date Id Summary Products Score Patch Annotated
2019-10-16 CVE-2019-17609 HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter. Hongcms N/A
2019-10-16 CVE-2019-17608 HongCMS 3.0.0 has XSS via the install/index.php dbname parameter. Hongcms N/A
2019-10-16 CVE-2019-17607 HongCMS 3.0.0 has XSS via the install/index.php servername parameter. Hongcms N/A
2019-02-17 CVE-2019-8407 HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI. Hongcms 6.5
2018-09-10 CVE-2018-16774 HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete. Hongcms 7.5
2018-06-29 CVE-2018-13021 An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI. Hongcms 7.2
2018-06-27 CVE-2018-12912 An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI. Hongcms 7.2
2018-06-13 CVE-2018-12266 system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code. Hongcms 6.1
2018-04-26 CVE-2018-10422 An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field. Hongcms 4.8
2018-04-21 CVE-2018-10265 An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI. Hongcms 8.8