Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2011-2706

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
Attacker Value
Unknown

CVE-2011-3857

Disclosure Date: September 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
0
Attacker Value
Unknown

CVE-2010-2926

Disclosure Date: July 30, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown

CVE-2010-2716

Disclosure Date: July 13, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.
0
Attacker Value
Unknown

CVE-2009-2581

Disclosure Date: July 23, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
0
Attacker Value
Unknown

CVE-2008-6595

Disclosure Date: April 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4703

Disclosure Date: October 23, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.
0
Attacker Value
Unknown

CVE-2008-1413

Disclosure Date: March 20, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
0
Attacker Value
Unknown

CVE-2007-5834

Disclosure Date: November 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post.
0
Attacker Value
Unknown

CVE-2007-5835

Disclosure Date: November 05, 2007 (last updated October 04, 2023)
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access.
0