cbcvebase.

Boesch-It Simpnews vulnerabilities

4 known vulnerabilities affecting boesch-it/simpnews.

Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2010-2858P4MEDIUMCVSS 4.3PoC≤ 2.47.03v2.0.1+30 more2010-07-25
CVE-2010-2858 [MEDIUM] CWE-79 CVE-2010-2858: Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allo Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
nvd
CVE-2007-4874P4MEDIUMCVSS 4.3PoCv2.41.032007-09-26
CVE-2007-4874 [MEDIUM] CWE-79 CVE-2007-4874: Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to in Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.
nvd
CVE-2007-5128P4MEDIUMCVSS 5.0v2.41.032007-09-27
CVE-2007-5128 [MEDIUM] CWE-20 CVE-2007-5128: SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensit SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.
nvd
CVE-2010-2859P4MEDIUMCVSS 5.0≤ 2.47.03v2.0.1+30 more2010-07-25
CVE-2010-2859 [MEDIUM] CWE-200 CVE-2010-2859: news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.
nvd
Boesch-It Simpnews vulnerabilities | cvebase