Перейти к содержимому
Noroxi

Записи newsphp

8 опубликованных записей вендора newsphp.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    8 записей
    • CVE-2004-2689
      41В плане

      NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.

      КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

      newsphp · newsphp31 дек. 2004 г.

    • CVE-2004-2690
      35Наблюдать

      Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and exec

      ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %

      newsphp · newsphp31 дек. 2004 г.

    • CVE-2003-0754
      31Наблюдать

      nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array,

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      newsphp · newsphp20 окт. 2003 г.

    • CVE-2006-0413
      30Наблюдать

      Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss,

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      newsphp · newsphp25 янв. 2006 г.

    • CVE-2006-3359
      30Наблюдать

      Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via th

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      newsphp · newsphp6 июл. 2006 г.

    • CVE-2006-3358
      27Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script o

      СредняяCVSS 6,8Proof of conceptEPSS 2 %

      newsphp · newsphp6 июл. 2006 г.

    • CVE-2003-0753
      21Наблюдать

      nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_conf

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      newsphp · newsphp20 окт. 2003 г.

    • CVE-2004-2688
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      newsphp · newsphp31 дек. 2004 г.