MiniCMS icon indicating copy to clipboard operation
MiniCMS copied to clipboard

至简的个人网站内容管理系统

Results 17 MiniCMS issues
Sort by recently updated
recently updated
newest added

vulnerability location:date parameter /MiniCMS-1.11/mc-admin/page.php?state=draft&date=2024-04 Payload: alert(123) Access the address with payload after login: /MiniCMS-1.11/mc-admin/page.php?state=draft&date=2024-04alert(123) Then we can find it triggering the xss vulnerability:

尊敬的作者:请问这个cms能承载多少篇文章?如果文章写到9000篇的话,加载速度会不会比较慢,效率低了? 另外cms的安全性怎么样,黑客会找漏洞攻击吗?

1、Download source code audit,It was found that the date parameter in the post.php file was not filtered during output. ```php # line 245 function goto_page(e) { var evt = e...

environment: - php.7.3.4 - win10 First,you need to Login the backstage here: /mc-admin/ ![image](https://user-images.githubusercontent.com/63861767/178090196-1c6482b4-080f-4ccd-9e5f-ee7103f6d3ae.png) Second,use payload: /mc-admin/post-edit.php?id=%3Cscript%3Ealert%285%29%3C/script%3E ![image](https://user-images.githubusercontent.com/63861767/178090338-6d98cc90-f0a5-492d-9356-d3c4cf4be06c.png) you will see Pop-ups,then click here : ![image](https://user-images.githubusercontent.com/63861767/178090374-84b91b60-37b3-433e-bdb3-89b49860b821.png) you will see Web...

Deprecated: Methods with the same name as their class will not be constructors in a future version of PHP; Markdown_Parser has a deprecated constructor in /home/ftp/f/fgjqikdf/wwwroot/mc-files/markdown.php on line 223 Deprecated:...

First , Click to enter the creation page ![image](https://user-images.githubusercontent.com/73013511/145502664-b71365dd-4432-49bd-8131-a68c7329d10a.png) Then, enter XSS payload in the content bar and Remember to choose publish ![image](https://user-images.githubusercontent.com/73013511/145502794-fabeef7a-02a2-4aaf-a84f-ea2490ca3d28.png) Click to view ![image](https://user-images.githubusercontent.com/73013511/145502849-18c02dee-4be9-4725-81e3-6a5d0149a9ee.png) OK! ![image](https://user-images.githubusercontent.com/73013511/145502882-df6b87d6-272c-4288-bf89-45834f612d6b.png)

![image](https://user-images.githubusercontent.com/35628593/134152606-2d6369fd-baed-4708-823f-cd020269a962.png) ![image](https://user-images.githubusercontent.com/35628593/134152656-12a44540-e138-4eef-9e86-bccd9831ec54.png)

![图片](https://user-images.githubusercontent.com/42528382/66576893-0fe34b80-ebab-11e9-8af7-b3b5fec611ef.png) revise admin password ![图片](https://user-images.githubusercontent.com/42528382/66577001-373a1880-ebab-11e9-887d-f1d0412cc357.png)

use CSRF vulnerability to delete multiple pages it was found in mc-admin/page.php.This vulnerability is similar to CVE-2019-9603 but at a different place. 1. if admin create new page like ccc,aaa...

One: use CSRF vulnerability to delete article Vulnerability details: When the administrator logs in, opening the webpage will automatically delete the specified article. Vulnerability url: http://127.0.0.1/MiniCMS/mc-admin/post.php Vulnerability POC: