Filtered by vendor Mini-nuke Subscriptions
Filtered by product Cms System Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2006-0199 1 Mini-nuke 1 Cms System 2024-08-07 N/A
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
CVE-2006-0203 1 Mini-nuke 1 Cms System 2024-08-07 N/A
membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.