Vulnerabilities (CVE)

Filtered by vendor Mini-nuke Subscribe
Filtered by product Cms System
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0203 1 Mini-nuke 1 Cms System 2024-02-28 5.0 MEDIUM N/A
membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.
CVE-2006-0199 1 Mini-nuke 1 Cms System 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.