Skip to main content

Vendor archive

c-news.fr CVEs

Beta · best-effort

3 CVEs tagged to vendor c-news.fr0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2008-2219

Published May 14, 2008

Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4629

Published Sep 8, 2006

PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4639

Published Sep 8, 2006

Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code vi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1