Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2012-5537
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
0
Attacker Value
Unknown
CVE-2007-4872
Disclosure Date: September 27, 2007 (last updated October 04, 2023)
SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.
0
Attacker Value
Unknown
CVE-2007-4873
Disclosure Date: September 27, 2007 (last updated October 04, 2023)
SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
0
Attacker Value
Unknown
CVE-2007-2598
Disclosure Date: May 11, 2007 (last updated October 04, 2023)
SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
0
Attacker Value
Unknown
CVE-2002-2143
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.
0
Attacker Value
Unknown
CVE-2002-2319
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
0
Attacker Value
Unknown
CVE-2002-2320
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.
0