Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php, (6) colorchooser.php, (7) colorwheel.php, (8) dbfiles.php, (9) diraccess.php, (10) faq.php, (11) index.php, (12) kb.php, and (13) stats.php.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| boesch-it | faqengine | 4.24.00 |
Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| boesch-it | simpnews | 2.36.00 |
| boesch-it | simpnews | 2.41.02 |
| boesch-it | simpnews | 2.44.00 |
| boesch-it | simpnews | 2.38.02 |
| boesch-it | simpnews | 2.38.04 |
| boesch-it | simpnews | 2.47.00 |
| boesch-it | simpnews | 2.0.1 |
| boesch-it | simpnews | 2.34.01 |
| boesch-it | simpnews | 2.38.03 |
| boesch-it | simpnews | 2.41.03 |
| boesch-it | simpnews | 2.31.0 |
| boesch-it | simpnews | 2.40.01 |
| boesch-it | simpnews | 2.30.2 |
| boesch-it | simpnews | 2.34.0 |
| boesch-it | simpnews | 2.30 |
| boesch-it | simpnews | 2.13 |
| boesch-it | simpnews | 2.42.01 |
| boesch-it | simpnews | * |
| boesch-it | simpnews | 2.33.01 |
| boesch-it | simpnews | 2.42.0 |
| boesch-it | simpnews | 2.37.00 |
| boesch-it | simpnews | 2.37.01 |
| boesch-it | simpnews | 2.32.0 |
| boesch-it | simpnews | 2.33.0 |
| boesch-it | simpnews | 2.41.0 |
| boesch-it | simpnews | 2.30.6 |
| boesch-it | simpnews | 2.35.00 |
| boesch-it | simpnews | 2.38 |
| boesch-it | simpnews | 2.32.1 |
| boesch-it | simpnews | 2.34 |
| boesch-it | simpnews | 2.39.0 |
| boesch-it | simpnews | 2.37.02 |
news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| boesch-it | simpnews | 2.36.00 |
| boesch-it | simpnews | 2.41.02 |
| boesch-it | simpnews | 2.44.00 |
| boesch-it | simpnews | 2.38.02 |
| boesch-it | simpnews | 2.38.04 |
| boesch-it | simpnews | 2.47.00 |
| boesch-it | simpnews | 2.0.1 |
| boesch-it | simpnews | 2.34.01 |
| boesch-it | simpnews | 2.38.03 |
| boesch-it | simpnews | 2.41.03 |
| boesch-it | simpnews | 2.31.0 |
| boesch-it | simpnews | 2.40.01 |
| boesch-it | simpnews | 2.30.2 |
| boesch-it | simpnews | 2.34.0 |
| boesch-it | simpnews | 2.30 |
| boesch-it | simpnews | 2.13 |
| boesch-it | simpnews | 2.42.01 |
| boesch-it | simpnews | * |
| boesch-it | simpnews | 2.33.01 |
| boesch-it | simpnews | 2.42.0 |
| boesch-it | simpnews | 2.37.00 |
| boesch-it | simpnews | 2.37.01 |
| boesch-it | simpnews | 2.32.0 |
| boesch-it | simpnews | 2.33.0 |
| boesch-it | simpnews | 2.41.0 |
| boesch-it | simpnews | 2.30.6 |
| boesch-it | simpnews | 2.35.00 |
| boesch-it | simpnews | 2.38 |
| boesch-it | simpnews | 2.32.1 |
| boesch-it | simpnews | 2.34 |
| boesch-it | simpnews | 2.39.0 |
| boesch-it | simpnews | 2.37.02 |