Stphp / Easynews
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-3331 | Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that… | MEDIUM | 5.0 | Jun 21, 2007 |
| CVE-2007-3330 | Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is sto… | MEDIUM | 4.3 | Jun 21, 2007 |
| CVE-2006-6866 | STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, ema… | HIGH | 7.8 | Jan 4, 2007 |
Showing 1 to 3 of 3 CVEs