VYPR

Phpfreenews

by Phpfreenews

CVEs (2)

  • CVE-2005-2637Aug 23, 2005
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.

  • CVE-2005-2638Aug 23, 2005
    risk 0.03cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php.