Vulnerabilities > Simplenews

DATE CVE VULNERABILITY TITLE RISK
2007-09-27 CVE-2007-4873 Permissions, Privileges, and Access Controls vulnerability in Simplenews 2.41.03
SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrary .inc files via a direct request, as demonstrated by admin/includes/dbtables.inc.
network
low complexity
simplenews CWE-264
5.0
2007-09-27 CVE-2007-4872 Information Disclosure vulnerability in Simplenews 2.41.03
SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.
network
low complexity
simplenews
5.0