Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Hongcms Project:
>> Hongcms
>> 3.0.0
Security Vulnerabilities
CVE-2020-21252
Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.
CVSS Score
8.8
EPSS Score
0.006
Published
2023-06-20
CVE-2020-21643
Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.
CVSS Score
6.1
EPSS Score
0.001
Published
2023-04-28
CVE-2022-32411
An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-07-01
CVE-2022-32412
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-07-01
CVE-2022-28523
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
CVSS Score
8.1
EPSS Score
0.004
Published
2022-04-26
CVE-2020-21431
HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.
CVSS Score
6.5
EPSS Score
0.003
Published
2021-10-04
CVE-2019-17607
HongCMS 3.0.0 has XSS via the install/index.php servername parameter.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-16
CVE-2019-17608
HongCMS 3.0.0 has XSS via the install/index.php dbname parameter.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-16
CVE-2019-17609
HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-16
CVE-2019-17610
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-16
Next
Page 1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved