6.8
CVSSv2

CVE-2006-3358

Published: 06/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote malicious users to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.

Vulnerable Product Search on Vulmon Subscribe to Product

newsphp newsphp 2006_pro

Exploits

source: wwwsecurityfocuscom/bid/18726/info NewsPHP 2006 PRO is prone to multiple input-validation vulnerabilities The issues include cross-site scripting and SQL-injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input A successful exploit of these vulnerabilities could ...
source: wwwsecurityfocuscom/bid/18726/info NewsPHP 2006 PRO is prone to multiple input-validation vulnerabilities The issues include cross-site scripting and SQL-injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input A successful exploit of these vulnerabilities could a ...