Show filters
87 Total Results
Displaying 71-80 of 87
Sort by:
Attacker Value
Unknown
CVE-2006-0157
Disclosure Date: January 10, 2006 (last updated February 22, 2025)
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.
0
Attacker Value
Unknown
CVE-2005-1582
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.
0
Attacker Value
Unknown
CVE-2005-1583
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.
0
Attacker Value
Unknown
CVE-2005-0800
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.
0
Attacker Value
Unknown
CVE-2004-0358
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.
0
Attacker Value
Unknown
CVE-2002-2143
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.
0
Attacker Value
Unknown
CVE-2002-1753
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
0
Attacker Value
Unknown
CVE-2002-2319
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
0
Attacker Value
Unknown
CVE-2002-2320
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.
0
Attacker Value
Unknown
CVE-2002-2249
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.
0