CVE-2004-1846 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.7% (pctl 76)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.67% — more likely to be exploited than 76% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-03-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| expinion.net | news manager lite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Expinion.net News Manager Lite 2.5 - 'more.asp?ID' SQL Injection | 2004-03-20 |
| exploit-db | Expinion.net News Manager Lite 2.5 - 'category_news.asp?ID' SQL Injection | 2004-03-20 |
| exploit-db | Expinion.net News Manager Lite 2.5 - 'news_sort.asp?filter' SQL Injection | 2004-03-20 |
References
- http://marc.info/?l=bugtraq&m=107999733503496&w=2
- http://secunia.com/advisories/11180
- http://securitytracker.com/id?1009507
- http://www.osvdb.org/4495
- http://www.osvdb.org/4496
- http://www.osvdb.org/4497
- http://www.securityfocus.com/bid/9935
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15549
- http://marc.info/?l=bugtraq&m=107999733503496&w=2
- http://secunia.com/advisories/11180
- http://securitytracker.com/id?1009507
- http://www.osvdb.org/4495
- http://www.osvdb.org/4496
- http://www.osvdb.org/4497
- http://www.securityfocus.com/bid/9935
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15549
→ the Explorer · watch your stack · NVD