Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2009-0739

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.
0
Attacker Value
Unknown

CVE-2008-1295

Disclosure Date: March 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter.
0
Attacker Value
Unknown

CVE-2008-0723

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.
0
Attacker Value
Unknown

CVE-2007-2520

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.
0
Attacker Value
Unknown

CVE-2007-2372

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.
0
Attacker Value
Unknown

CVE-2007-2371

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.
0
Attacker Value
Unknown

CVE-2007-2325

Disclosure Date: April 27, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
0
Attacker Value
Unknown

CVE-2007-2014

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.
0
Attacker Value
Unknown

CVE-2007-0633

Disclosure Date: January 31, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.
0
Attacker Value
Unknown

CVE-2006-5261

Disclosure Date: October 12, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4) index.php3 in include/.
0