Описание
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-0693
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34539
- http://secunia.com/advisories/25438
- http://securityreason.com/securityalert/2740
- http://www.netvigilance.com/advisory0022
- http://www.osvdb.org/34227
- http://www.securityfocus.com/archive/1/469828/100/0/threaded
- http://www.securityfocus.com/bid/24201
- http://www.vupen.com/english/advisories/2007/1981
EPSS
Процентиль: 83%
0.01932
Низкий
CVE ID
Связанные уязвимости
nvd
больше 18 лет назад
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
EPSS
Процентиль: 83%
0.01932
Низкий