s-cms kayıtları
s-cms üreticisine ait 42 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')19
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-707 Improper Neutralization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
42 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-10708Kavram kanıtı | S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %2,6 | 2 Nis 2019 |
39İzleyin | CVE-2021-37270İstismar yok | There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0.s-cms · cms enterprise website construction system · CWE-862 | Kritik9,8 | — | %1,5 | 27 Eyl 2021 |
39İzleyin | CVE-2018-18427İstismar yok | s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,2 | 17 Eki 2018 |
39İzleyin | CVE-2019-6805İstismar yok | SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,1 | 25 Oca 2019 |
39İzleyin | CVE-2018-18887İstismar yok | S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,1 | 31 Eki 2018 |
39İzleyin | CVE-2018-20477İstismar yok | An issue was discovered in S-CMS 3.0.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,1 | 25 Ara 2018 |
39İzleyin | CVE-2018-20479İstismar yok | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,1 | 25 Ara 2018 |
39İzleyin | CVE-2018-20480İstismar yok | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,1 | 25 Ara 2018 |
39İzleyin | CVE-2022-23336İstismar yok | S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %1,1 | 14 Şub 2022 |
39İzleyin | CVE-2023-51048İstismar yok | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %0,5 | 21 Ara 2023 |
39İzleyin | CVE-2023-51049İstismar yok | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %0,5 | 21 Ara 2023 |
39İzleyin | CVE-2023-51052İstismar yok | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %0,5 | 21 Ara 2023 |
39İzleyin | CVE-2023-51051İstismar yok | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %0,5 | 21 Ara 2023 |
39İzleyin | CVE-2023-51050İstismar yok | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Kritik9,8 | — | %0,5 | 21 Ara 2023 |
36İzleyin | CVE-2018-18426İstismar yok | s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.phs-cms · s-cms · CWE-94 | Yüksek8,8 | — | %2,4 | 17 Eki 2018 |
35İzleyin | CVE-2019-10237İstismar yok | S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a relateds-cms · s-cms · CWE-352 | Yüksek8,8 | — | %0,6 | 27 Mar 2019 |
35İzleyin | CVE-2019-9040İstismar yok | S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-201s-cms · s-cms · CWE-352 | Yüksek8,8 | — | %0,6 | 23 Şub 2019 |
35İzleyin | CVE-2023-7191İstismar yok | S-CMS reg.php sql injections-cms · s-cms · CWE-89 | Yüksek8,8 | — | %0,5 | 31 Ara 2023 |
35İzleyin | CVE-2023-7189İstismar yok | A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006.s-cms · s-cms · CWE-89 | Yüksek8,8 | — | %0,5 | 31 Ara 2023 |
35İzleyin | CVE-2023-7190İstismar yok | A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006.s-cms · s-cms · CWE-89 | Yüksek8,8 | — | %0,5 | 31 Ara 2023 |
35İzleyin | CVE-2018-19332İstismar yok | An issue was discovered in S-CMS v1.5.s-cms · s-cms · CWE-352 | Yüksek8,8 | — | %0,5 | 17 Kas 2018 |
30İzleyin | CVE-2020-20340İstismar yok | A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database infors-cms · s-cms · CWE-89 | Yüksek7,5 | — | %1,3 | 1 Eyl 2021 |
30İzleyin | CVE-2020-19954İstismar yok | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.s-cms · s-cms · CWE-611 | Yüksek7,5 | — | %1,2 | 14 Eki 2021 |
30İzleyin | CVE-2018-20018İstismar yok | S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.s-cms · s-cms · CWE-89 | Yüksek7,5 | — | %1,2 | 10 Ara 2018 |
30İzleyin | CVE-2018-20478İstismar yok | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-200 | Yüksek7,5 | — | %1,2 | 25 Ara 2018 |
- CVE-2019-1070840Planlayın
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %3s-cms · s-cms2 Nis 2019
- CVE-2021-3727039İzleyin
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · cms enterprise website construction system27 Eyl 2021
- CVE-2018-1842739İzleyin
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms17 Eki 2018
- CVE-2019-680539İzleyin
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms25 Oca 2019
- CVE-2018-1888739İzleyin
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms31 Eki 2018
- CVE-2018-2047739İzleyin
An issue was discovered in S-CMS 3.0.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms25 Ara 2018
- CVE-2018-2047939İzleyin
An issue was discovered in S-CMS 1.0.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms25 Ara 2018
- CVE-2018-2048039İzleyin
An issue was discovered in S-CMS 1.0.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms25 Ara 2018
- CVE-2022-2333639İzleyin
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms14 Şub 2022
- CVE-2023-5104839İzleyin
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms21 Ara 2023
- CVE-2023-5104939İzleyin
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms21 Ara 2023
- CVE-2023-5105239İzleyin
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms21 Ara 2023
- CVE-2023-5105139İzleyin
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms21 Ara 2023
- CVE-2023-5105039İzleyin
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.
KritikCVSS 9,8İstismar yokEPSS %1s-cms · s-cms21 Ara 2023
- CVE-2018-1842636İzleyin
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.ph
YüksekCVSS 8,8İstismar yokEPSS %2s-cms · s-cms17 Eki 2018
- CVE-2019-1023735İzleyin
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related
YüksekCVSS 8,8İstismar yokEPSS %1s-cms · s-cms27 Mar 2019
- CVE-2019-904035İzleyin
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-201
YüksekCVSS 8,8İstismar yokEPSS %1s-cms · s-cms23 Şub 2019
- CVE-2023-719135İzleyin
S-CMS reg.php sql injection
YüksekCVSS 8,8İstismar yokEPSS %0s-cms · s-cms31 Ara 2023
- CVE-2023-718935İzleyin
A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006.
YüksekCVSS 8,8İstismar yokEPSS %0s-cms · s-cms31 Ara 2023
- CVE-2023-719035İzleyin
A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006.
YüksekCVSS 8,8İstismar yokEPSS %0s-cms · s-cms31 Ara 2023
- CVE-2018-1933235İzleyin
An issue was discovered in S-CMS v1.5.
YüksekCVSS 8,8İstismar yokEPSS %0s-cms · s-cms17 Kas 2018
- CVE-2020-2034030İzleyin
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database infor
YüksekCVSS 7,5İstismar yokEPSS %1s-cms · s-cms1 Eyl 2021
- CVE-2020-1995430İzleyin
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
YüksekCVSS 7,5İstismar yokEPSS %1s-cms · s-cms14 Eki 2021
- CVE-2018-2001830İzleyin
S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
YüksekCVSS 7,5İstismar yokEPSS %1s-cms · s-cms10 Ara 2018
- CVE-2018-2047830İzleyin
An issue was discovered in S-CMS 1.0.
YüksekCVSS 7,5İstismar yokEPSS %1s-cms · s-cms25 Ara 2018