VendorsVirtuasystemsvirtuanews_pro1.0.1
Vulnerabilities

Virtuasystems Virtuanews Pro 1.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2004-0358
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.
Published 2004-03-18 · Modified
6.81 PoCEPSS 0.042