Show filters
87 Total Results
Displaying 41-50 of 87
Sort by:
Attacker Value
Unknown

CVE-2008-0653

Disclosure Date: February 07, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.
0
Attacker Value
Unknown

CVE-2007-6541

Disclosure Date: December 27, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action to the default URI in patch/.
0
Attacker Value
Unknown

CVE-2007-6540

Disclosure Date: December 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.
0
Attacker Value
Unknown

CVE-2007-5050

Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter.
0
Attacker Value
Unknown

CVE-2007-4603

Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action.
0
Attacker Value
Unknown

CVE-2007-2598

Disclosure Date: May 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
0
Attacker Value
Unknown

CVE-2007-2303

Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
0
Attacker Value
Unknown

CVE-2007-1438

Disclosure Date: March 13, 2007 (last updated October 04, 2023)
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-1248

Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.
0
Attacker Value
Unknown

CVE-2006-7081

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3.
0