VendorsBoesch-itsimpnewsall versions
Vulnerabilities

Boesch-it Simpnews

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2007-5128
SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.
Published 2007-09-27 · Modified
5.0EPSS 0.012
CVE-2010-2859
news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.
Published 2010-07-23 · Modified
5.0EPSS 0.012
CVE-2007-4874
Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.
Published 2007-09-26 · Modified
4.32 PoCEPSS 0.018
CVE-2010-2858
Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
Published 2010-07-23 · Modified
4.31 PoCEPSS 0.017