Vulnerabilities > Phpnews

DATE CVE VULNERABILITY TITLE RISK
2007-03-02 CVE-2006-7081 Remote File Include vulnerability in PHPnews 1.0
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3.
network
low complexity
phpnews
7.5
2006-12-07 CVE-2006-6357 Cross-Site Scripting vulnerability in PHPNews
Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
phpnews
6.8
2006-12-07 CVE-2006-6356 Cross-Site Scripting vulnerability in PHPnews 1.3
Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter.
network
phpnews
6.8
2005-07-26 CVE-2005-2383 SQL Injection vulnerability in PHPnews 1.2.5
SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.
network
low complexity
phpnews
7.5
2005-07-06 CVE-2005-2156 SQL Injection vulnerability in PHPnews 1.2.5
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
network
low complexity
phpnews
7.5
2005-03-01 CVE-2005-0632 Remote File Include vulnerability in PHPnews 1.2.3/1.2.4
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.
network
low complexity
phpnews
5.0
2004-12-31 CVE-2004-2474 SQL Injection vulnerability in PHPnews 1.2.3
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.
network
low complexity
phpnews
7.5