Skip to main content

Vendor/product archive

matteoiammarrone / s-cms CVEs

Beta · best-effort

5 CVEs tagged to matteoiammarrone / s-cms0 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2010-4772

Published Mar 23, 2011

Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4771

Published Mar 23, 2011

SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1502

Published May 1, 2009

Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequence…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0864

Published Mar 10, 2009

S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0863

Published Mar 10, 2009

SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1