CVE-2006-0199
Published Jan 13, 2006SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
Vendor/product archive
2 CVEs tagged to mini-nuke / cms_system — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other…