Wenming Jiang

3 exploits Active since Apr 2018
CVE-2018-9038 EXPLOITDB MEDIUM text WORKING POC
Monstra - Path Traversal
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.
CVSS 6.5
CVE-2018-10109 EXPLOITDB MEDIUM text WORKING POC
Monstra CMS 3.0.4 - XSS
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.
CVSS 4.8
CVE-2018-10321 EXPLOITDB MEDIUM text WORKING POC
Frog CMS 0.9.5 - XSS
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
CVSS 4.8