CVE-2008-7172 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.29% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-09-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| yanick bourbeau | lightweight news portal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Lightweight news portal (LNP) 1.0b - Multiple Vulnerabilities | 2008-06-20 |
References
→ the Explorer · watch your stack · NVD