← Back

Xpression News

xpression_news

Vendor: Xpression News • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xpression News
1Xpression News
Apr 23, 2026
Feb 21, 2007
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in...Show more
Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Xpression News
1Xpression News
Apr 23, 2026
Feb 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.