CVE-2002-2319 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 82)
Patch early
A public exploit exists.
Description
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.25% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| mysimplenews | mysimplenews |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MySimpleNews 1.0 - PHP Injection | 2002-10-02 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0027.html
- http://www.iss.net/security_center/static/10296.php
- http://www.securityfocus.com/bid/5865
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0027.html
- http://www.iss.net/security_center/static/10296.php
- http://www.securityfocus.com/bid/5865
→ the Explorer · watch your stack · NVD