Vulnerabilities > Phpnews
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-03-02 | CVE-2006-7081 | Remote File Include vulnerability in PHPnews 1.0 Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3. | 7.5 |
2006-12-07 | CVE-2006-6357 | Cross-Site Scripting vulnerability in PHPNews Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. network phpnews | 6.8 |
2006-12-07 | CVE-2006-6356 | Cross-Site Scripting vulnerability in PHPnews 1.3 Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter. network phpnews | 6.8 |
2005-07-26 | CVE-2005-2383 | SQL Injection vulnerability in PHPnews 1.2.5 SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request. | 7.5 |
2005-07-06 | CVE-2005-2156 | SQL Injection vulnerability in PHPnews 1.2.5 SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter. | 7.5 |
2005-03-01 | CVE-2005-0632 | Remote File Include vulnerability in PHPnews 1.2.3/1.2.4 PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter. | 5.0 |
2004-12-31 | CVE-2004-2474 | SQL Injection vulnerability in PHPnews 1.2.3 SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php. | 7.5 |