Vulnerabilities > Ucms Project

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-28440 Unrestricted Upload of File with Dangerous Type vulnerability in Ucms Project Ucms 1.6
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
ucms-project CWE-434
6.5
2022-04-21 CVE-2022-28443 Unspecified vulnerability in Ucms Project Ucms 1.6
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
network
low complexity
ucms-project
6.4
2022-04-21 CVE-2022-28444 Path Traversal vulnerability in Ucms Project Ucms 1.6
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
network
low complexity
ucms-project CWE-22
5.0
2021-09-29 CVE-2020-20781 Cross-site Scripting vulnerability in Ucms Project Ucms 1.4.7
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
3.5
2021-07-23 CVE-2021-25809 Information Exposure vulnerability in Ucms Project Ucms 1.5.0
UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.
network
low complexity
ucms-project CWE-200
5.0
2020-11-30 CVE-2020-25537 Unrestricted Upload of File with Dangerous Type vulnerability in Ucms Project Ucms 1.5.0
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
network
low complexity
ucms-project CWE-434
critical
10.0
2020-10-23 CVE-2020-25483 Command Injection vulnerability in Ucms Project Ucms 1.4.8
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
network
low complexity
ucms-project CWE-77
7.5
2020-09-04 CVE-2020-24981 Incorrect Authorization vulnerability in Ucms Project Ucms 1.4.8
An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8.
network
low complexity
ucms-project CWE-863
5.0
2019-05-21 CVE-2019-12251 SQL Injection vulnerability in Ucms Project Ucms 1.4.7
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
network
low complexity
ucms-project CWE-89
6.5
2019-03-07 CVE-2018-16804 Cross-site Scripting vulnerability in Ucms Project Ucms 1.4.6
An issue was discovered in UCMS 1.4.6.
4.3