4.3
CVSSv2

CVE-2010-4772

Published: 23/03/2011 Updated: 24/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote malicious users to inject arbitrary web script or HTML via the id parameter to viewforum.php.

Vulnerable Product Search on Vulmon Subscribe to Product

matteoiammarrone s-cms 2.5

Exploits

# ============================================================ # Exploit Title: S-CMS Multiple Vuln # Date: 14/11/2010 # Author: LordTittiS # Greetings To: God_Of_Pain, System_Overide # Software Link: wwwmatteoiammarronecom # wwwmatteoiammarronecom/public/s-cms/ # Vulnerability Type: Full Path Disclosure / SQL Injection / Cross Si ...