VYPR

Litenews

by Wogan May

CVEs (2)

  • CVE-2008-3508Aug 7, 2008
    risk 0.03cvss epss 0.03

    LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.

  • CVE-2008-3507Aug 7, 2008
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.