mingSoft
27 exploits
Active since Sep 2018
MCMS 4.6.5 - Cross-Site Request Forgery
mingSoft MCMS <5.2.4 - Info Disclosure
Mingsoft MCMS v5.2.9 - SQL Injection via categoryType Parameter
Mingsoft MCMS < 5.3.1 - Cross-Site Scripting via search.do Style Parameter
MCMS < 5.2.11 - Arbitrary File Write via ms/template/writeFileContent.do
Mingsoft MCMS 5.2.9 - Cross-Site Scripting in Article Handler Save Function
Mingsoft MCMS <5.2.9 - SQL Injection
Mingsoft MCMS 5.2.8 - Cross-Site Scripting via search.do content_title Parameter
Mingsoft MCMS 5.2.8 - SQL Injection
MCMS 5.2.7 - Arbitrary File Upload via ZIP File
Mingsoft MCMS 5.2.7 - SQL Injection via /mdiy/dict/list orderBy Parameter
Mingsoft MCMS v5.2.7 - SQL Injection via /mdiy/dict/listExcludeApp orderBy Parameter
Mingsoft MCMS <5.2.7 - SQL Injection
MCMS 4.6.5 - Path Traversal and Arbitrary File Write via URL Parameter
MCMS 4.6.5 - Unauthenticated Arbitrary File Upload via FileAction.java
MCMS v5.2.4 - SQL Injection via search.do Parameter
MCMS v5.2.4 - Arbitrary File Upload via /ms/template/writeFileContent.do
MCMS v5.2.4 - SQL Injection via /ms/mdiy/model/importJson.do
MCMS < 5.2.9 - Remote Code Execution via Template Management
MCMS v5.2.4 - Arbitrary File Upload via New Template Module
MCMS v5.2.4 - Remote Code Execution via Hardcoded Shiro Key
mingsoft mcms < 5.2.5 - Remote Code Execution via JSPX Webshell Upload
MCMS <=5.2.5 - SQL Injection via FormDataAction#queryData
MCMS <=5.2.5 - Unauthenticated Remote Code Execution via Freemarker Template Utility
MCMS <=5.2.5 - SQL Injection via DictAction#list Parameter