Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2012-5537

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
0
Attacker Value
Unknown

CVE-2007-4872

Disclosure Date: September 27, 2007 (last updated October 04, 2023)
SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.
0
Attacker Value
Unknown

CVE-2007-4873

Disclosure Date: September 27, 2007 (last updated October 04, 2023)
SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
0
Attacker Value
Unknown

CVE-2007-2598

Disclosure Date: May 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
0
Attacker Value
Unknown

CVE-2002-2143

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.
0
Attacker Value
Unknown

CVE-2002-2319

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
0
Attacker Value
Unknown

CVE-2002-2320

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.
0