Vulnerabilities (CVE)

Filtered by vendor Matthew Dingley Subscribe
Filtered by product Md News
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1755 1 Matthew Dingley 1 Md News 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-1756 1 Matthew Dingley 1 Md News 2024-02-04 7.5 HIGH N/A
MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area.