CVE-2007-0261 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 4.7% (pctl 92)
Patch early
A public exploit exists.
Description
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 4.75% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-01-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| snews | snews |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | sNews 1.5.30 - Remote Reset Admin Pass / Command Execution | 2007-01-12 |
References
- http://osvdb.org/32817
- http://secunia.com/advisories/23746
- http://www.securityfocus.com/bid/22025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31535
- https://www.exploit-db.com/exploits/3116
- http://osvdb.org/32817
- http://secunia.com/advisories/23746
- http://www.securityfocus.com/bid/22025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31535
- https://www.exploit-db.com/exploits/3116
→ the Explorer · watch your stack · NVD