Vulnerabilities > Newsphp

DATE CVE VULNERABILITY TITLE RISK
2006-07-06 CVE-2006-3359 Input Validation vulnerability in Newsphp 2006Pro
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.
network
low complexity
newsphp
7.5
2006-07-06 CVE-2006-3358 Input Validation vulnerability in Newsphp 2006Pro
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page.
network
newsphp
6.8
2006-01-25 CVE-2006-0413 SQL Injection vulnerability in Newsphp
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.
network
low complexity
newsphp CWE-89
7.5
2004-12-31 CVE-2004-2690 File-Upload vulnerability in newsPHP
Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.
network
newsphp
8.5
2004-12-31 CVE-2004-2689 Permissions, Privileges, and Access Controls vulnerability in Newsphp
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
network
low complexity
newsphp CWE-264
critical
10.0
2004-12-31 CVE-2004-2688 Cross-Site Scripting vulnerability in Newsphp
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
network
newsphp CWE-79
4.3
2003-10-20 CVE-2003-0754 Security Bypass vulnerability in newsPHP
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
network
low complexity
newsphp
7.5
2003-10-20 CVE-2003-0753 Remote Security vulnerability in newsPHP
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
network
low complexity
newsphp
5.0