phpnews records
7 published records for vendor phpnews.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-7081Proof of concept | Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include paramphpnews · phpnews | High7.5 | — | 2.7% | Mar 2, 2007 |
30Monitor | CVE-2004-2474No exploit | SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriendphpnews · phpnews | High7.5 | — | 1.2% | Dec 31, 2004 |
30Monitor | CVE-2005-2383Proof of concept | SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter inphpnews · phpnews | High7.5 | — | 1.2% | Jul 26, 2005 |
30Monitor | CVE-2005-2156No exploit | SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parametephpnews · phpnews | High7.5 | — | 1.1% | Jul 6, 2005 |
28Monitor | CVE-2006-6356Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary wphpnews · phpnews | Medium6.8 | — | 2.0% | Dec 6, 2006 |
27Monitor | CVE-2006-6357No exploit | Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary phpnews · phpnews | Medium6.8 | — | 1.1% | Dec 6, 2006 |
21Monitor | CVE-2005-0632Proof of concept | PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP cophpnews · phpnews | Medium5.0 | — | 2.6% | Mar 1, 2005 |
- CVE-2006-708131Monitor
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include param
HighCVSS 7.5Proof of conceptEPSS 3%phpnews · phpnewsMar 2, 2007
- CVE-2004-247430Monitor
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend
HighCVSS 7.5No exploitEPSS 1%phpnews · phpnewsDec 31, 2004
- CVE-2005-238330Monitor
SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in
HighCVSS 7.5Proof of conceptEPSS 1%phpnews · phpnewsJul 26, 2005
- CVE-2005-215630Monitor
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext paramete
HighCVSS 7.5No exploitEPSS 1%phpnews · phpnewsJul 6, 2005
- CVE-2006-635628Monitor
Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary w
MediumCVSS 6.8Proof of conceptEPSS 2%phpnews · phpnewsDec 6, 2006
- CVE-2006-635727Monitor
Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary
MediumCVSS 6.8No exploitEPSS 1%phpnews · phpnewsDec 6, 2006
- CVE-2005-063221Monitor
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP co
MediumCVSS 5.0Proof of conceptEPSS 3%phpnews · phpnewsMar 1, 2005