Vulnerabilities > Boesch IT > Simpnews > 2.33.0

DATE CVE VULNERABILITY TITLE RISK
2010-07-25 CVE-2010-2859 Information Exposure vulnerability in Boesch-It Simpnews
news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.
network
low complexity
boesch-it CWE-200
5.0
2010-07-25 CVE-2010-2858 Cross-Site Scripting vulnerability in Boesch-It Simpnews
Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
network
boesch-it CWE-79
4.3