Skip to main content

Vendor/product archive

expinion.net / news_manager_lite CVEs

Beta · best-effort

3 CVEs tagged to expinion.net / news_manager_lite0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2004-1845

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1846

Published Mar 20, 2004

Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to cate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1847

Published Mar 20, 2004

News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1