CVE-2002-2319

Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mysimplenews:mysimplenews:1.0:*:*:*:*:*:*:*

Information

Published : 2002-12-30 21:00

Updated : 2008-09-05 13:32


NVD link : CVE-2002-2319

Mitre link : CVE-2002-2319


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

mysimplenews

  • mysimplenews