News Manager 2.0 Multiple Vulnerabilities
News Manager 2.0 is vulnerable to multiple vulnerabilities including Remote File Include, Remote File Disclosure, Remote SQL Injection, and Remote Permission Bypass. The Remote File Include vulnerability is present in the ch_readalso.php file, which allows an attacker to include a remote file. The Remote File Disclosure vulnerability is present in the attachments.php file, which allows an attacker to view the contents of a file on the server. The Remote SQL Injection vulnerabilities are present in the list_tagitems.php, advsearch.php, archive.php, and index.php files, which allow an attacker to inject malicious SQL queries. The Remote Permission Bypass vulnerability is present in the db/connect_str.php file, which allows an attacker to bypass authentication and gain access to the database. Additionally, an attacker can view the PHPINFO page by accessing the login/info.php file.