Description
Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
Exploits (1)
References (6)
Scores
EPSS
0.0107
EPSS Percentile
77.9%
Details
Status
published
Products (1)
corenews/corenews
< 2.0.1
Published
Apr 26, 2006
Tracked Since
Feb 18, 2026