Steven M. Christey

2 exploits Active since Apr 2006
EIP-2026-112167 EXPLOITDB text WRITEUP
Simpnews 2.x - 'Wap_short_news.php' Remote File Inclusion
CVE-2006-1925 EXPLOITDB text WRITEUP
CuteNews 1.4.1 - Directory Traversal and Cross-Site Scripting via Editnews Source Parameter
Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.