Admin News Tools
Adminnewstools · 2 CVEs
CVE-2009-2558
HIGH
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post new…
Jul 21, 2009
CVE-2009-2557
MEDIUM
Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitr…
Jul 21, 2009
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2009-2558 | system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request. | HIGH | 2.42% | Jul 21, 2009 |
| CVE-2009-2557 | Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fich… | MEDIUM | 6.78% | Jul 21, 2009 |
Showing 1 to 2 of 2 CVEs