Vulnerabilities > Florian Amrhein

DATE CVE VULNERABILITY TITLE RISK
2006-05-24 CVE-2006-2557 Remote PHP Script Code Injection vulnerability in Florian Amrhein Newsportal 0.36
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
network
low complexity
florian-amrhein
6.4
2006-05-24 CVE-2006-2556 Cross-Site Scripting vulnerability in Florian Amrhein Newsportal 0.36
Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
florian-amrhein
5.8