Fantastic News
Vendor:
First CVE: Nov 26, 2005 · Active for 20 years
5
Total CVEs
More Total CVEs than 79% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fantastic News over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2005
20 years ago
Most Recent CVE
Sep 11, 2006
7,259 days ago
CVE Severity & Scoring
Fantastic News5 CVEs
40%
60%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3846HIGH SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | Nov 26, 2005 | 7.5 | 30 | NO | YES |
CVE-2006-4285HIGH PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] p | Aug 22, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-4671MEDIUM PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONFI | Sep 11, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-0972MEDIUM SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vec | Mar 3, 2006 | 5.0 | 22 | NO | YES |
CVE-2006-1154HIGH PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 | Mar 10, 2006 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
80.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Fantastic News
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.5 | 1 | 7.5 | 3.1% | 0 | 1 |
| 2.1.4 | 1 | 7.5 | 2.8% | 0 | 0 |
| 2.1.3 | 2 | 7.2 | 2.9% | 0 | 2 |
| 2.1.2 | 3 | 7.3 | 2.9% | 0 | 2 |
| 2.1.1 | 4 | 6.7 | 2.5% | 0 | 3 |