Unrated severityNVD Advisory· Published May 1, 2009· Updated Apr 23, 2026
CVE-2009-1502
CVE-2009-1502
Description
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
Affected products
2cpe:2.3:a:matteoiammarrone:s-cms:1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:matteoiammarrone:s-cms:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:matteoiammarrone:s-cms:1.5.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/34771nvdExploit
- secunia.com/advisories/34940nvdVendor Advisory
- www.exploit-db.com/exploits/8566nvd
News mentions
0No linked articles in our index yet.