Vulnerabilities > Solucija > Snews > 1.3

DATE CVE VULNERABILITY TITLE RISK
2006-02-15 CVE-2006-0716 Input Validation vulnerability in Solucija Snews 1.3
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
network
low complexity
solucija
7.5
2006-02-15 CVE-2006-0715 Input Validation vulnerability in Solucija Snews 1.3
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
network
solucija
4.3