Vulnerabilities > CVE-2006-3359 - Unspecified vulnerability in Newsphp 2006Pro

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
newsphp
exploit available

Summary

Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.

Vulnerable Configurations

Part Description Count
Application
Newsphp
1

Exploit-Db

descriptionnewsPHP 2006 PRO inc/rss_feed.php category Parameter SQL Injection. CVE-2006-3359. Webapps exploit for php platform
idEDB-ID:28134
last seen2016-02-03
modified2006-06-29
published2006-06-29
reportersecurityconnection
sourcehttps://www.exploit-db.com/download/28134/
titlenewsPHP 2006 PRO inc/rss_feed.php category Parameter SQL Injection