7.5
CVSSv2

CVE-2013-7349

Published: 01/04/2014 Updated: 31/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote malicious users to execute arbitrary SQL commands via the (1) news_id parameter to news/send.php, (2) thread_id parameter to posts/edit.php, or (3) user_email parameter to users/password.php or (4) users/register.php. NOTE: these issues were SPLIT from CVE-2013-5640 due to differences in researchers and disclosure dates.

Vulnerable Product Search on Vulmon Subscribe to Product

raoul proenca gnew 2013.1

Exploits

Gnew v20131 Multiple XSS And SQL Injection Vulnerabilities Vendor: Raoul Proença Product web page: wwwgnewfr Affected version: 20131 Summary: Gnew is a simple Content Management System written with PHP language and using a database server (MySQL, PostgreSQL or SQLite) for storage Desc: Input passed via several parameters is not pr ...
Advisory ID: HTB23171 Product: Gnew Vendor: Raoul Proença Vulnerable Version(s): 20131 and probably prior Tested Version: 20131 Advisory Publication: August 28, 2013 [without technical details] Vendor Notification: August 28, 2013 Public Disclosure: October 2, 2013 Vulnerability Type: PHP File Inclusion [CWE-98], SQL Injection [CWE-89] CVE Ref ...