Unrated severityNVD Advisory· Published Oct 25, 2012· Updated Apr 29, 2026
CVE-2011-5220
CVE-2011-5220
Description
Cross-site scripting (XSS) vulnerability in templates/default/Admin/Login.html in PHP-SCMS 1.6.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter to index.php.
Affected products
2cpe:2.3:a:cristopher_shi:php-scms:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cristopher_shi:php-scms:*:*:*:*:*:*:*:*range: <=1.6.8
- cpe:2.3:a:cristopher_shi:php-scms:1.6.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.