Xfairguy Codeavalanche News vulnerabilities
3 known vulnerabilities affecting xfairguy/codeavalanche_news.
Total CVEs
3
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2007-1021P3CRITICALCVSS 10.0PoCv1.x2007-02-21
CVE-2007-1021 [CRITICAL] CVE-2007-1021: SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to
SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.
nvd
CVE-2006-2499P3HIGHCVSS 7.5PoCv1.22006-05-20
CVE-2006-2499 [HIGH] CVE-2006-2499: SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attacker
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
nvd
CVE-2006-2500P4MEDIUMCVSS 6.8v1.22006-05-20
CVE-2006-2500 [MEDIUM] CVE-2006-2500: Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows r
Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field. NOTE: if this issue is limited to administrators, and if it is expected behavior for administrators to be able to generate HTML, then this is not a vulnerability.
nvd