7.5
CVSSv2

CVE-2005-3846

Published: 26/11/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in news.php in Fantastic News 2.1.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the category parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

fscripts fantastic news

Exploits

source: wwwsecurityfocuscom/bid/15622/info Fantastic News is prone to an SQL injection vulnerability Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation Fantastic News 211 and prior ...