CVE-2023-29962
- EPSS 0.1%
- Veröffentlicht 04.01.2024 06:15:45
- Zuletzt bearbeitet 03.06.2025 15:15:25
S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.
CVE-2023-7191
- EPSS 0.05%
- Veröffentlicht 31.12.2023 16:15:44
- Zuletzt bearbeitet 21.11.2024 08:45:28
A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file member/reg.php. The manipulation of the argument M_login/M_email leads to sql injection. The exploit has ...
CVE-2023-7190
- EPSS 0.05%
- Veröffentlicht 31.12.2023 16:15:44
- Zuletzt bearbeitet 21.11.2024 08:45:28
A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown functionality of the file /member/ad.php?action=ad. The manipulation of the argument A_text/A_url/A_co...
CVE-2023-7189
- EPSS 0.05%
- Veröffentlicht 31.12.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:45:28
A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an unknown functionality of the file /s/index.php?action=statistics. The manipulation of the argument lid leads to sql injec...
CVE-2023-51052
- EPSS 0.12%
- Veröffentlicht 21.12.2023 16:15:11
- Zuletzt bearbeitet 24.04.2025 15:15:55
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.
CVE-2023-51051
- EPSS 0.28%
- Veröffentlicht 21.12.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:37:45
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.
CVE-2023-51050
- EPSS 0.28%
- Veröffentlicht 21.12.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:37:45
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.
CVE-2023-51049
- EPSS 0.28%
- Veröffentlicht 21.12.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:37:45
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.
CVE-2023-51048
- EPSS 0.28%
- Veröffentlicht 21.12.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:37:45
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.
CVE-2023-29963
- EPSS 1.5%
- Veröffentlicht 05.05.2023 23:15:09
- Zuletzt bearbeitet 29.01.2025 21:15:17
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.