Neeke/HongCMS

Neeke/HongCMS

Releases0
Stars23
HongCMS中英文网站系统是一个轻量级的网站系统,访问速度极快,使用简单。程序代码简洁严谨,完全免费开源。 可用于建设各种类型的中英文网站,同时它是一个小型开发框架.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.

6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.

7.2 HIGH6.5 MEDIUM

An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.

7.2 HIGH6.5 MEDIUM

An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.

8.1 HIGH5.5 MEDIUM

HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

6.5 MEDIUM5.5 MEDIUM

HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.

9.8 CRITICAL7.5 HIGH

Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."

6.5 MEDIUM5.5 MEDIUM

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)

5.5 MEDIUM

HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.

6.4 MEDIUM

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.

9 HIGH

An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI.

6.5 MEDIUM

An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.

3.5 LOW

An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field.

6.8 MEDIUM

An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.