CVE-2006-5090 – Phoenix Evolution CMS - '/modules/pageedit/index.php?pageid' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2006-5090
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Phoenix Evolution CMS (PECMS) permite a un atacante remoto inyectar secuencias de comandos web o HTML de sue elección a través de los parámetros (1)mod o (2)action en index.php, o el parámetro (3)pageid en modules/pageedit/index.php. NOTA: el origen de esta información es desconocido; los detalles se obtuvieron de terceras fuentes de información. • https://www.exploit-db.com/exploits/28693 https://www.exploit-db.com/exploits/28692 http://osvdb.org/33676 http://osvdb.org/33677 http://www.securityfocus.com/bid/20212 •
CVE-2002-2249 – News Evolution 1.0/2.0 - Include Undefined Variable Command Execution
https://notcve.org/view.php?id=CVE-2002-2249
PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php. • https://www.exploit-db.com/exploits/22048 http://marc.info/?l=bugtraq&m=103835200230127&w=2 http://www.securityfocus.com/bid/6260 https://exchange.xforce.ibmcloud.com/vulnerabilities/10709 • CWE-94: Improper Control of Generation of Code ('Code Injection') •