sh-news CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

sh-news vulnerability overview

Aggregates CVE and security vulnerability intelligence across all sh-news-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk sql injection, with potential vendor impact data exposure across vendor surface software deployment and vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2007-6391 SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. [email protected] 7.5 0.99% 2007-12-17 2026-06-16
CVE-2006-6801 PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the news_cfg[path] parameter. [email protected] 6.8 2.01% 2006-12-28 2026-06-16
CVE-2006-5282 Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive.php, (3) comments.php, (4) init.php, or (5) news.php. [email protected] 7.5 3.36% 2006-10-13 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence