Vulnerabilities > Boesch IT

DATE CVE VULNERABILITY TITLE RISK
2010-07-25 CVE-2010-2859 Information Exposure vulnerability in Boesch-It Simpnews
news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.
network
low complexity
boesch-it CWE-200
5.0
2010-07-25 CVE-2010-2858 Cross-Site Scripting vulnerability in Boesch-It Simpnews
Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
network
boesch-it CWE-79
4.3
2010-04-13 CVE-2010-1360 Code Injection vulnerability in Boesch-It Faqengine 4.24.00
Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php, (6) colorchooser.php, (7) colorwheel.php, (8) dbfiles.php, (9) diraccess.php, (10) faq.php, (11) index.php, (12) kb.php, and (13) stats.php.
network
low complexity
boesch-it CWE-94
7.5
2007-09-27 CVE-2007-5130 Improper Input Validation vulnerability in Boesch-It Simpgb 1.46.02
SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which reveals the path in various error messages.
network
boesch-it CWE-20
4.3
2007-09-27 CVE-2007-5129 Information Exposure vulnerability in Boesch-It Simpgb 1.46.02
SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via a direct request for admin/cfginfo.php; and (2) download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
network
low complexity
boesch-it CWE-200
5.0
2007-09-27 CVE-2007-5128 Improper Input Validation vulnerability in multiple products
SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.
network
low complexity
boesch-it php CWE-20
5.0
2007-09-26 CVE-2007-4874 Cross-Site Scripting vulnerability in Boesch-It Simpnews 2.41.03
Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.
network
boesch-it CWE-79
4.3