VYPR

Mcnews

by Mcnews

CVEs (2)

  • CVE-2005-0800May 2, 2005
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

  • CVE-2005-0720Mar 8, 2005
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.