AOH :: HP Unsorted V :: B06-1546.HTM

Vnews multiple vulnerabilities
VNews Multiple Vulnerabilities
VNews Multiple Vulnerabilities

New eVuln Advisory:
VNews Multiple Vulnerabilities 

eVuln ID: EV0112
CVE: CVE-2006-1543 CVE-2006-1544 CVE-2006-1545
Software: VNews
Sowtware's Web Site: 
Versions: 1.2
Critical Level: Dangerous
Type: Multiple Vulnerabilities
Class: Remote
Status: Unpatched. No reply from developer(s)
PoC/Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (

1. SQL Injection.

Vulnerable scripts:

Parameters loginvar(admin/admin.php), news(news.php), nom(news.php) are not properly sanitized before being used in SQL queries. This can be used to evaluate arbitrary SQL expression(admin/admin.php) or make any SQL query by injecting arbitrary SQL code(news.php).

Condition: magic_quotes_gpc = off

2. Multiple Cross-Site Scripting.

Vulnerable Script: news.php

Parameters autorkomentarza, tresckomentarza are not properly sanitized. This can be used to post arbitrary HTML or web script code.

3. PHP Code Insertion.

Administrator has an ability to edit variable values from admin/config.php file. This can be used to insert arbitrary PHP code into config file which executes by every php-script.

System access is possible.

Condition: magic_quotes_gpc = off

Available at: 

No Patch available.

Discovered by: Aliaksandr Hartsuyeu (

Aliaksandr Hartsuyeu - Penetration Testing Services 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH
We do not send spam. If you have received spam bearing an email address, please forward it with full headers to