Vulnerabilities > Web4Future > News Portal

DATE CVE VULNERABILITY TITLE RISK
2006-05-09 CVE-2006-2244 SQL-Injection vulnerability in News Portal
Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php.
network
low complexity
web4future
6.4
2006-05-09 CVE-2006-2243 Cross-Site Scripting vulnerability in News Portal
Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php.
network
web4future
5.8