First published: Wed Dec 26 2018(Updated: )
An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20478 is a vulnerability discovered in S-CMS 1.0 that allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension.
CVE-2018-20478 affects S-CMS 1.0, allowing an attacker to read sensitive files on the server.
CVE-2018-20478 has a severity rating of 7.5, which is considered high.
An attacker can exploit CVE-2018-20478 by manipulating the DownName parameter in the admin/download.php file, allowing them to read sensitive files.
Yes, a fix for CVE-2018-20478 is available. It is recommended to update to a patched version of S-CMS or apply the necessary security patches.