Skip to main content

Vendor/product archive

scriptphp / pronews CVEs

Beta · best-effort

3 CVEs tagged to scriptphp / pronews0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2006-6580

Published Dec 15, 2006

admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and pos…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6518

Published Dec 14, 2006

Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6519

Published Dec 14, 2006

SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1