S_CMS 2.5 - Multiple Vulnerabilities ID: 15588 CVE: 2010-4772, 2010-4771 Author: LORDTITTIS Type: WEBAPPS Date: 2010-11-20 Platform: PHP Vulnerable App: S_CMS 2.5 Vulnerability Details Vulnerability Type: Full Path Disclosure / SQL Injection / Cross Site Scripting Vulnerable File: Vulnerable Parameter: Exploit Examples 1. Full Path Disclosure (FPD) 2. SQL Injection 3. Cross Site Scripting (XSS) Advisory/Source Link: Advisory Link