Home/Product/solucija snews
Product

solucija snews

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2016-20052
<= 1.7
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files i
9.8CRITICAL
CVE-2016-20051
<= 1.7
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials withou
5.3MEDIUM
CVE-2011-2706
<= 1.7.1
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
6.1MEDIUM
CVE-2010-2926
all versions
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category p
CVE-2008-1413
all versions
Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary
CVE-2007-0261
all versions
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform u
CVE-2006-3916
all versions
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary
CVE-2006-0716
all versions
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) catego
CVE-2006-0715
all versions
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comme
CVE-2005-3853
<= 1.3
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
threatengine.sh