Phpmywind

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 22
    Known Exploited: 0
    0
    Critical Level Threats
    9
    High Level Threats
    13
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-21400

    SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.

    Last Modified: Dec 10, 2024
    Published: Jun 20, 2023

    CVE-2020-21060

    SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.

    Last Modified: Feb 13, 2025
    Published: Apr 04, 2023

    CVE-2020-19964

    A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.

    Last Modified: Nov 21, 2024
    Published: Oct 14, 2021

    CVE-2021-39503

    PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.

    Last Modified: Nov 21, 2024
    Published: Sep 07, 2021

    CVE-2020-18886

    Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

    Last Modified: Nov 21, 2024
    Published: Aug 20, 2021
    Items Per Page