Vulnerabilities > Vscripts PL

DATE CVE VULNERABILITY TITLE RISK
2006-04-02 CVE-2006-1576 Input Validation vulnerability in Vscripts.Pl Qlnews 1.2
Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.
network
low complexity
vscripts-pl
7.5
2006-04-02 CVE-2006-1575 Input Validation vulnerability in Vscripts.Pl Qlnews 1.2
Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters.
network
vscripts-pl
6.8