Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown
CVE-2011-2706
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
0
Attacker Value
Unknown
CVE-2011-3857
Disclosure Date: September 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
0
Attacker Value
Unknown
CVE-2010-2926
Disclosure Date: July 30, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown
CVE-2010-2716
Disclosure Date: July 13, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.
0
Attacker Value
Unknown
CVE-2009-2581
Disclosure Date: July 23, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
0
Attacker Value
Unknown
CVE-2008-6595
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-4703
Disclosure Date: October 23, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.
0
Attacker Value
Unknown
CVE-2008-1413
Disclosure Date: March 20, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
0
Attacker Value
Unknown
CVE-2007-5834
Disclosure Date: November 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post.
0
Attacker Value
Unknown
CVE-2007-5835
Disclosure Date: November 05, 2007 (last updated October 04, 2023)
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access.
0