Vulnerabilities > Easyscripts > TR Script News > 2.1

DATE CVE VULNERABILITY TITLE RISK
2008-04-25 CVE-2008-1958 Code Injection vulnerability in Easyscripts TR Script News 2.1
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension.
network
low complexity
easyscripts CWE-94
6.5
2008-04-25 CVE-2008-1957 SQL Injection vulnerability in Easyscripts TR Script News 2.1
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.
network
low complexity
easyscripts CWE-89
7.5