Vulnerabilities
Vulnerable Software
Joyplus-Cms Project:  >> Joyplus-Cms  Security Vulnerabilities
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
CVSS Score
7.5
EPSS Score
0.0
Published
2023-06-20
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
CVSS Score
7.5
EPSS Score
0.003
Published
2021-08-18
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-10-04
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-07-22
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2018-07-18
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-07-18
manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alter the flow of control. Consequently, one can upload and execute a .php file, a similar issue to CVE-2018-8766.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-07-17
joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-06-27
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring.
CVSS Score
9.8
EPSS Score
0.087
Published
2018-06-07
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-04-13


Contact Us

Shodan ® - All rights reserved