
CVE-2023-29962
https://notcve.org/view.php?id=CVE-2023-29962
04 Jan 2024 — S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability. Se descubrió que S-CMS v5.0 contenía una vulnerabilidad de lectura de archivos arbitraria. • https://gist.github.com/superjock1988/546df50f8251cb2c99adda4351098528 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-7191 – S-CMS reg.php sql injection
https://notcve.org/view.php?id=CVE-2023-7191
31 Dec 2023 — A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file member/reg.php. The manipulation of the argument M_login/M_email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249393 was assigned to this vulnerability. • https://note.zhaoj.in/share/Fmytf7wBINbP • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-7190 – S-CMS sql injection
https://notcve.org/view.php?id=CVE-2023-7190
31 Dec 2023 — A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown functionality of the file /member/ad.php?action=ad. The manipulation of the argument A_text/A_url/A_contact leads to sql injection. The exploit has been disclosed to the public and may be used. • https://note.zhaoj.in/share/0ZY7hEQAskqM • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-7189 – S-CMS sql injection
https://notcve.org/view.php?id=CVE-2023-7189
31 Dec 2023 — A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an unknown functionality of the file /s/index.php?action=statistics. The manipulation of the argument lid leads to sql injection. The exploit has been disclosed to the public and may be used. • https://note.zhaoj.in/share/9yaojoQvesLu • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-51048
https://notcve.org/view.php?id=CVE-2023-51048
21 Dec 2023 — S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php. Se descubrió que S-CMS v5.0 contenía una vulnerabilidad de inyección SQL a través del parámetro A_newsauth en /admin/ajax.php. • https://www.notion.so/scms5-0-sql-injection-94c791a563d1481a9439fa98a1bc9a1b • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-51049
https://notcve.org/view.php?id=CVE-2023-51049
21 Dec 2023 — S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php. Se descubrió que S-CMS v5.0 contenía una vulnerabilidad de inyección SQL a través del parámetro A_bbsauth en /admin/ajax.php. • https://www.notion.so/scms5-0-sql-injection-94c791a563d1481a9439fa98a1bc9a1b • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-51050
https://notcve.org/view.php?id=CVE-2023-51050
21 Dec 2023 — S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php. Se descubrió que S-CMS v5.0 contenía una vulnerabilidad de inyección SQL a través del parámetro A_productauth en /admin/ajax.php. • https://www.notion.so/scms5-0-sql-injection-94c791a563d1481a9439fa98a1bc9a1b • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-51051
https://notcve.org/view.php?id=CVE-2023-51051
21 Dec 2023 — S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php. Se descubrió que S-CMS v5.0 contenía una vulnerabilidad de inyección SQL a través del parámetro A_textauth en /admin/ajax.php. • https://www.notion.so/scms5-0-sql-injection-94c791a563d1481a9439fa98a1bc9a1b • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-51052
https://notcve.org/view.php?id=CVE-2023-51052
21 Dec 2023 — S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php. Se descubrió que S-CMS v5.0 contenía una vulnerabilidad de inyección SQL a través del parámetro A_formauth en /admin/ajax.php. • https://www.notion.so/scms5-0-sql-injection-94c791a563d1481a9439fa98a1bc9a1b • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-29963
https://notcve.org/view.php?id=CVE-2023-29963
05 May 2023 — S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php. • https://github.com/superjock1988/debug/blob/main/s-cms_rce.md • CWE-94: Improper Control of Generation of Code ('Code Injection') •