Записи s-cms
42 опубликованных записей вендора s-cms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')19
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-707 Improper Neutralization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
42 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-10708Proof of concept | S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 2,6 % | 2 апр. 2019 г. |
39Наблюдать | CVE-2021-37270Эксплойта нет | There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0.s-cms · cms enterprise website construction system · CWE-862 | Критическая9,8 | — | 1,5 % | 27 сент. 2021 г. |
39Наблюдать | CVE-2018-18427Эксплойта нет | s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,2 % | 17 окт. 2018 г. |
39Наблюдать | CVE-2019-6805Эксплойта нет | SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,1 % | 25 янв. 2019 г. |
39Наблюдать | CVE-2018-18887Эксплойта нет | S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,1 % | 31 окт. 2018 г. |
39Наблюдать | CVE-2018-20477Эксплойта нет | An issue was discovered in S-CMS 3.0.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,1 % | 25 дек. 2018 г. |
39Наблюдать | CVE-2018-20479Эксплойта нет | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,1 % | 25 дек. 2018 г. |
39Наблюдать | CVE-2018-20480Эксплойта нет | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,1 % | 25 дек. 2018 г. |
39Наблюдать | CVE-2022-23336Эксплойта нет | S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 1,1 % | 14 февр. 2022 г. |
39Наблюдать | CVE-2023-51048Эксплойта нет | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 0,5 % | 21 дек. 2023 г. |
39Наблюдать | CVE-2023-51049Эксплойта нет | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 0,5 % | 21 дек. 2023 г. |
39Наблюдать | CVE-2023-51052Эксплойта нет | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 0,5 % | 21 дек. 2023 г. |
39Наблюдать | CVE-2023-51051Эксплойта нет | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 0,5 % | 21 дек. 2023 г. |
39Наблюдать | CVE-2023-51050Эксплойта нет | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Критическая9,8 | — | 0,5 % | 21 дек. 2023 г. |
36Наблюдать | CVE-2018-18426Эксплойта нет | s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.phs-cms · s-cms · CWE-94 | Высокая8,8 | — | 2,4 % | 17 окт. 2018 г. |
35Наблюдать | CVE-2019-10237Эксплойта нет | S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a relateds-cms · s-cms · CWE-352 | Высокая8,8 | — | 0,6 % | 27 мар. 2019 г. |
35Наблюдать | CVE-2019-9040Эксплойта нет | S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-201s-cms · s-cms · CWE-352 | Высокая8,8 | — | 0,6 % | 23 февр. 2019 г. |
35Наблюдать | CVE-2023-7191Эксплойта нет | S-CMS reg.php sql injections-cms · s-cms · CWE-89 | Высокая8,8 | — | 0,5 % | 31 дек. 2023 г. |
35Наблюдать | CVE-2023-7189Эксплойта нет | A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006.s-cms · s-cms · CWE-89 | Высокая8,8 | — | 0,5 % | 31 дек. 2023 г. |
35Наблюдать | CVE-2023-7190Эксплойта нет | A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006.s-cms · s-cms · CWE-89 | Высокая8,8 | — | 0,5 % | 31 дек. 2023 г. |
35Наблюдать | CVE-2018-19332Эксплойта нет | An issue was discovered in S-CMS v1.5.s-cms · s-cms · CWE-352 | Высокая8,8 | — | 0,5 % | 17 нояб. 2018 г. |
30Наблюдать | CVE-2020-20340Эксплойта нет | A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database infors-cms · s-cms · CWE-89 | Высокая7,5 | — | 1,3 % | 1 сент. 2021 г. |
30Наблюдать | CVE-2020-19954Эксплойта нет | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.s-cms · s-cms · CWE-611 | Высокая7,5 | — | 1,2 % | 14 окт. 2021 г. |
30Наблюдать | CVE-2018-20018Эксплойта нет | S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.s-cms · s-cms · CWE-89 | Высокая7,5 | — | 1,2 % | 10 дек. 2018 г. |
30Наблюдать | CVE-2018-20478Эксплойта нет | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-200 | Высокая7,5 | — | 1,2 % | 25 дек. 2018 г. |
- CVE-2019-1070840В плане
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %s-cms · s-cms2 апр. 2019 г.
- CVE-2021-3727039Наблюдать
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · cms enterprise website construction system27 сент. 2021 г.
- CVE-2018-1842739Наблюдать
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms17 окт. 2018 г.
- CVE-2019-680539Наблюдать
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms25 янв. 2019 г.
- CVE-2018-1888739Наблюдать
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms31 окт. 2018 г.
- CVE-2018-2047739Наблюдать
An issue was discovered in S-CMS 3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms25 дек. 2018 г.
- CVE-2018-2047939Наблюдать
An issue was discovered in S-CMS 1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms25 дек. 2018 г.
- CVE-2018-2048039Наблюдать
An issue was discovered in S-CMS 1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms25 дек. 2018 г.
- CVE-2022-2333639Наблюдать
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms14 февр. 2022 г.
- CVE-2023-5104839Наблюдать
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms21 дек. 2023 г.
- CVE-2023-5104939Наблюдать
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms21 дек. 2023 г.
- CVE-2023-5105239Наблюдать
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms21 дек. 2023 г.
- CVE-2023-5105139Наблюдать
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms21 дек. 2023 г.
- CVE-2023-5105039Наблюдать
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %s-cms · s-cms21 дек. 2023 г.
- CVE-2018-1842636Наблюдать
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.ph
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %s-cms · s-cms17 окт. 2018 г.
- CVE-2019-1023735Наблюдать
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %s-cms · s-cms27 мар. 2019 г.
- CVE-2019-904035Наблюдать
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-201
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %s-cms · s-cms23 февр. 2019 г.
- CVE-2023-719135Наблюдать
S-CMS reg.php sql injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %s-cms · s-cms31 дек. 2023 г.
- CVE-2023-718935Наблюдать
A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %s-cms · s-cms31 дек. 2023 г.
- CVE-2023-719035Наблюдать
A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %s-cms · s-cms31 дек. 2023 г.
- CVE-2018-1933235Наблюдать
An issue was discovered in S-CMS v1.5.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %s-cms · s-cms17 нояб. 2018 г.
- CVE-2020-2034030Наблюдать
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database infor
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %s-cms · s-cms1 сент. 2021 г.
- CVE-2020-1995430Наблюдать
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %s-cms · s-cms14 окт. 2021 г.
- CVE-2018-2001830Наблюдать
S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %s-cms · s-cms10 дек. 2018 г.
- CVE-2018-2047830Наблюдать
An issue was discovered in S-CMS 1.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %s-cms · s-cms25 дек. 2018 г.