CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2009-1665 MEDIUM

myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without spec…

CVSS 6.4 EPSS 2.33% May 17, 2009
CVE-2009-1664 HIGH

myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to chan…

CVSS 7.5 EPSS 2.05% May 17, 2009
CVE-2009-1663 MEDIUM

Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploadi…

CVSS 6.8 EPSS 2.85% May 17, 2009
CVE-2009-1655 MEDIUM

Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL co…

CVSS 6.5 EPSS 1.75% May 16, 2009
CVE-2009-1654 MEDIUM

Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web scrip…

CVSS 4.3 EPSS 1.48% May 16, 2009
CVE-2008-1958 MEDIUM

Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary cod…

CVSS 6.5 EPSS 3.30% Apr 25, 2008
CVE-2008-1957 HIGH

SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.

CVSS 7.5 EPSS 1.19% Apr 25, 2008
CVE-2001-1527 LOW

easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.

CVSS 2.1 EPSS 0.31% Jul 14, 2005
CVE-2001-1526 MEDIUM

Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script…

CVSS 4.3 EPSS 0.99% Jul 14, 2005
CVE-2001-1525 MEDIUM

Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly othe…

CVSS 5.0 EPSS 2.51% Jul 14, 2005
CVE-2001-1437 HIGH

easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which lea…

CVSS 7.5 EPSS 2.11% Apr 21, 2005

Showing 1 to 11 CVEs · page 1