Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

S Cms HIGH 7.5
CVE-2018-20478

An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a …

No fix yet
Fix from $1,950 2018-12-26
S Cms MEDIUM 6.1
CVE-2018-20476

An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter.

No fix yet
Fix from $1,600 2018-12-26
S Cms HIGH 7.5
CVE-2018-20018

S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.

No fix yet
Fix from $1,950 2018-12-10
S Cms HIGH 8.8
CVE-2018-19332

An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.

No fix yet
Fix from $1,950 2018-11-17
S Cms HIGH 7.5
CVE-2018-19331

An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.

Mitigation only
Fix from $1,950 2018-11-17
S Cms MEDIUM 6.1
CVE-2018-19145

An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.

No fix yet
Fix from $1,600 2018-11-09
S Cms CRITICAL 9.8
CVE-2018-18887

S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).

No fix yet
Fix from $2,300 2018-11-01
S Cms CRITICAL 9.8
CVE-2018-18427

s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.

No fix yet
Fix from $2,300 2018-10-17
S Cms HIGH 8.8
CVE-2018-18426

s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt par…

No fix yet
Fix from $1,950 2018-10-17