Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2021
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.
CVSS Score
8.1
EPSS Score
0.002
Published
2021-10-06
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.
CVSS Score
8.8
EPSS Score
0.031
Published
2021-10-06
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.
CVSS Score
9.8
EPSS Score
0.035
Published
2021-10-06
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.
CVSS Score
9.8
EPSS Score
0.03
Published
2021-10-06
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.
CVSS Score
9.1
EPSS Score
0.003
Published
2021-10-06
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
CVSS Score
7.2
EPSS Score
0.004
Published
2021-10-06
XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-10-06
An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-10-06
An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the setchange log.
CVSS Score
6.1
EPSS Score
0.008
Published
2021-10-06
An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript.
CVSS Score
4.8
EPSS Score
0.006
Published
2021-10-06


Contact Us

Shodan ® - All rights reserved