loadream/AyaCMS

loadream/AyaCMS

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases1
Frequency
Last Release
AyaCms是一款极其简单且自由的PHP建站系统

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH

AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.

8.8 HIGH

AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code.

9.8 CRITICAL

AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php

9.8 CRITICAL

AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php

9.8 CRITICAL

AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).

8.8 HIGH

AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.

9.8 CRITICAL

AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

7.2 HIGH6.5 MEDIUM

AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,

8.8 HIGH6.8 MEDIUM

Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.