Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2006-0972
Disclosure Date: March 03, 2006 (last updated February 22, 2025)
SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846.
0
Attacker Value
Unknown
CVE-2006-0723
Disclosure Date: February 16, 2006 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.
0
Attacker Value
Unknown
CVE-2006-0724
Disclosure Date: February 16, 2006 (last updated February 22, 2025)
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.
0
Attacker Value
Unknown
CVE-2006-0157
Disclosure Date: January 10, 2006 (last updated February 22, 2025)
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.
0
Attacker Value
Unknown
CVE-2005-3846
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown
CVE-1999-0868
Disclosure Date: February 20, 1997 (last updated February 22, 2025)
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
0
Attacker Value
Unknown
CVE-1999-0043
Disclosure Date: December 04, 1996 (last updated February 22, 2025)
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
0