Vulnerabilities > China ON Site > Flexphpnews

DATE CVE VULNERABILITY TITLE RISK
2009-01-21 CVE-2008-5927 SQL Injection vulnerability in China-On-Site Flexphpnews 0.0.6
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka username field) or (2) checkpass parameter (aka password field) to admin/index.php.
network
low complexity
china-on-site CWE-89
7.5
2005-05-02 CVE-2005-1237 SQL Injection vulnerability in FlexPHPNews News.PHP
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
network
low complexity
china-on-site
7.5