Vulnerabilities > C News FR

DATE CVE VULNERABILITY TITLE RISK
2008-05-14 CVE-2008-2219 Cross-Site Scripting vulnerability in C-News.Fr C-News 1.0.1
Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.
network
c-news-fr CWE-79
4.3
2006-09-08 CVE-2006-4639 Code Injection vulnerability in C-News.Fr C-News
Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) formulaire_commentaires.php, (2) affichage/liste_news.php, (3) affichage/news_complete.php, or (4) affichage/pagination.php.
network
high complexity
c-news-fr CWE-94
5.1
2006-09-08 CVE-2006-4629 Remote File Include vulnerability in C-News Path Parameter
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
network
low complexity
c-news-fr
7.5