Smartsitecms operates a content management system product with a modest vulnerability footprint centered on input-handling and credential-management issues, including SQL injection and hard-coded credentials that are characteristic of web application exposures. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartsitecms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3162HIGH PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root paramete | Jun 22, 2006 | 7.5 | 31 | NO | YES |
CVE-2009-0405HIGH SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter. | Feb 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-3421MEDIUM PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parame | Jul 7, 2006 | 5.1 | 24 | NO | YES |
CVE-2006-7074HIGH admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie. | Mar 2, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartsitecms.
Media articles that mention a CVE ID that affects a product developed by Smartsitecms — matched by CVE ID, not by vendor name.