7.5
CVSSv2

CVE-2008-2340

Published: 19/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote malicious users to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.

Vulnerable Product Search on Vulmon Subscribe to Product

news manager news manager 2.0

Exploits

News Manager 20 Multiple Vulnerabilities Script : superb-eastdlsourceforgenet/sourceforge/newsrssmanager/newsmanager20zip Dork : "Copyrights © 2005 Belgische Federale Overheidsdiensten" 1- Remote File Include Vulnerability /ch_readalsophp?read_xml_include=localhost/020txt 2- Remote File Disclosure Vulnerability /attachments ...