Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Reamday Enterprises Subscribe
Filtered by product Magic News Plus
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1141 1 Reamday Enterprises 1 Magic News Plus 2018-10-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter. NOTE: This issue may overlap CVE-2006-0723.
CVE-2007-1142 1 Reamday Enterprises 1 Magic News Plus 2018-10-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.
CVE-2006-0157 1 Reamday Enterprises 1 Magic News Plus 2008-09-05 5.0 MEDIUM N/A
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.