Vulnerabilities
Vulnerable Software
Joyplus-Cms Project:  >> Joyplus-Cms  Security Vulnerabilities
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-04-12
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
CVSS Score
5.3
EPSS Score
0.002
Published
2018-04-11
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add.
CVSS Score
9.8
EPSS Score
0.026
Published
2018-03-18
joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-03-18
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-03-15


Contact Us

Shodan ® - All rights reserved