easyscripts easynews CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting easyscripts easynews (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2001-1527 easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access. [email protected] 2.1 0.07% 2001-12-31 2026-04-16
CVE-2001-1526 Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. [email protected] 4.3 0.35% 2001-12-31 2026-04-16
CVE-2001-1525 Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter. [email protected] 5.0 4.43% 2001-12-31 2026-04-16
CVE-2001-1437 easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out. [email protected] 7.5 1.26% 2001-12-01 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence