Vulnerabilities > Cm68 News

DATE CVE VULNERABILITY TITLE RISK
2006-12-14 CVE-2006-6544 Cross-Site Scripting vulnerability in Cm68 News
Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
cm68-news
6.8
2006-12-11 CVE-2006-6462 Code Injection vulnerability in Cm68 News Cm68 News 12.02.06
PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.
network
low complexity
cm68-news CWE-94
7.5