Vulnerabilities
Vulnerable Software
Newsphp:  >> Newsphp  >> 2006_pro  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.
CVSS Score
6.8
EPSS Score
0.007
Published
2006-07-06
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.
CVSS Score
7.5
EPSS Score
0.006
Published
2006-07-06


Contact Us

Shodan ® - All rights reserved