Skip to main content

Vendor/product archive

stefan_ernst / newsscript CVEs

Beta · best-effort

4 CVEs tagged to stefan_ernst / newsscript0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2006-4766

Published Sep 13, 2006

Directory traversal vulnerability in print.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allows remote attackers to read arbitrary files via a .. (dot dot) in the ide para…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4767

Published Sep 13, 2006

Multiple directory traversal vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5beta allow remote attackers to (1) read arbitrary local files via a .. (dot dot) sequence…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4768

Published Sep 13, 2006

Multiple direct static code injection vulnerabilities in add_go.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4666

Published Sep 9, 2006

Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1