Vulnerabilities
Vulnerable Software
Dotnetindex:  >> Active News Manager  Security Vulnerabilities
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp.
CVSS Score
7.5
EPSS Score
0.015
Published
2006-11-24
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.
CVSS Score
7.5
EPSS Score
0.013
Published
2006-11-24
Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.
CVSS Score
4.3
EPSS Score
0.032
Published
2006-11-24
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.
CVSS Score
7.5
EPSS Score
0.006
Published
2005-05-31


Contact Us

Shodan ® - All rights reserved