newsphp records
8 published records for vendor newsphp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-2689No exploit | NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.newsphp · newsphp · CWE-264 | Critical10.0 | — | 2.2% | Dec 31, 2004 |
35Monitor | CVE-2004-2690No exploit | Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execnewsphp · newsphp | High8.5 | — | 2.4% | Dec 31, 2004 |
31Monitor | CVE-2003-0754No exploit | nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, newsphp · newsphp | High7.5 | — | 2.3% | Oct 20, 2003 |
30Monitor | CVE-2006-0413Proof of concept | Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss,newsphp · newsphp · CWE-89 | High7.5 | — | 1.3% | Jan 25, 2006 |
30Monitor | CVE-2006-3359Proof of concept | Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via thnewsphp · newsphp | High7.5 | — | 1.1% | Jul 6, 2006 |
27Monitor | CVE-2006-3358Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script onewsphp · newsphp | Medium6.8 | — | 1.6% | Jul 6, 2006 |
21Monitor | CVE-2003-0753No exploit | nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_confnewsphp · newsphp | Medium5.0 | — | 2.0% | Oct 20, 2003 |
17Monitor | CVE-2004-2688No exploit | Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_newsphp · newsphp · CWE-79 | Medium4.3 | — | 1.0% | Dec 31, 2004 |
- CVE-2004-268941Plan
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
CriticalCVSS 10.0No exploitEPSS 2%newsphp · newsphpDec 31, 2004
- CVE-2004-269035Monitor
Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and exec
HighCVSS 8.5No exploitEPSS 2%newsphp · newsphpDec 31, 2004
- CVE-2003-075431Monitor
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array,
HighCVSS 7.5No exploitEPSS 2%newsphp · newsphpOct 20, 2003
- CVE-2006-041330Monitor
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss,
HighCVSS 7.5Proof of conceptEPSS 1%newsphp · newsphpJan 25, 2006
- CVE-2006-335930Monitor
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via th
HighCVSS 7.5Proof of conceptEPSS 1%newsphp · newsphpJul 6, 2006
- CVE-2006-335827Monitor
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script o
MediumCVSS 6.8Proof of conceptEPSS 2%newsphp · newsphpJul 6, 2006
- CVE-2003-075321Monitor
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_conf
MediumCVSS 5.0No exploitEPSS 2%newsphp · newsphpOct 20, 2003
- CVE-2004-268817Monitor
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_
MediumCVSS 4.3No exploitEPSS 1%newsphp · newsphpDec 31, 2004