VYPR

Phpnewsmanager

Sign in to watch

by Skintech

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2004-03270.030.04Nov 23, 2004Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.
CVE-2006-15600.000.02Mar 31, 2006Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts. NOTE: portions of the description details are obtained from third party information.