Scriptphp / Pronews
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2006-6580 | admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information wit… | MEDIUM | 6.4 | Dec 15, 2006 |
| CVE-2006-6519 | SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter. | HIGH | 7.5 | Dec 14, 2006 |
| CVE-2006-6518 | Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email,… | MEDIUM | 6.8 | Dec 14, 2006 |
Showing 1 to 3 of 3 CVEs