Panews
PHP Arena · 3 CVEs
CVE-2005-0647
MEDIUM
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2…
Mar 4, 2005
CVE-2005-0646
HIGH
SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql…
Mar 4, 2005
CVE-2005-0485
MEDIUM
Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to injec…
Feb 19, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2005-0647 | admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which a… | MEDIUM | 4.15% | Mar 4, 2005 |
| CVE-2005-0646 | SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter. | HIGH | 1.14% | Mar 4, 2005 |
| CVE-2005-0485 | Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the… | MEDIUM | 1.83% | Feb 19, 2005 |
Showing 1 to 3 of 3 CVEs