Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2021-24342

Disclosure Date: June 07, 2021 (last updated February 22, 2025)
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.
Attacker Value
Unknown

CVE-2015-7342

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.
Attacker Value
Unknown

CVE-2015-7341

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
Attacker Value
Unknown

CVE-2015-7343

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
Attacker Value
Unknown

CVE-2013-1636

Disclosure Date: March 12, 2014 (last updated February 14, 2025)
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.
0
Attacker Value
Unknown

CVE-2012-4256

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2010-1950

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-1949

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information.
0