Vulnerabilities (CVE)

Filtered by vendor S-cms Subscribe
Filtered by product S-cms
Total 41 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20478 1 S-cms 1 S-cms 2024-02-28 5.0 MEDIUM 7.5 HIGH
An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.