Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2007-5303
Disclosure Date: October 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.
0
Attacker Value
Unknown
CVE-2007-3772
Disclosure Date: July 15, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter.
0
Attacker Value
Unknown
CVE-2007-0261
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.
0
Attacker Value
Unknown
CVE-2006-3916
Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
0
Attacker Value
Unknown
CVE-2006-1237
Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.
0
Attacker Value
Unknown
CVE-2006-0715
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
0
Attacker Value
Unknown
CVE-2006-0716
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
0
Attacker Value
Unknown
CVE-2005-3853
Disclosure Date: November 27, 2005 (last updated February 22, 2025)
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
0
Attacker Value
Unknown
CVE-2004-1665
Disclosure Date: September 05, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.
0
Attacker Value
Unknown
CVE-2002-1753
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
0