Back to search
CVE-2011-10009
Published: Aug 13, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.
| Vendor | Product | Versions |
|---|---|---|
S40 CMS | S40 CMS | affected 0.4.2 |
Weaknesses (CWE)
References
https://web.archive.org/web/20110613222630/http://y-osirys.com/security/exploits/id27
technical-description
exploit
https://www.vulncheck.com/advisories/s40-cms-path-traversal
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now