Vulnerabilities > Matteoiammarrone > S CMS > 2.5

DATE CVE VULNERABILITY TITLE RISK
2011-03-23 CVE-2010-4772 Cross-Site Scripting vulnerability in Matteoiammarrone S-Cms 2.5
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.
4.3
2011-03-23 CVE-2010-4771 SQL Injection vulnerability in Matteoiammarrone S-Cms 2.5
SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
matteoiammarrone CWE-89
7.5