Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Reamday Enterprises Subscribe
Filtered by product Magic News Lite
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0723 1 Reamday Enterprises 1 Magic News Lite 2017-07-19 2.6 LOW N/A
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.
CVE-2006-0724 1 Reamday Enterprises 1 Magic News Lite 2017-07-19 2.6 LOW N/A
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.