See how creacms compares to other vendors in security performance
Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[documenturi] parameter to administration/editionarticle/editionarticle.php and the (2) cfg[baseuriadmin] parameter to administration/fonctions/getlistelangue.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.