CVE-2007-0261

sNews <1.5.30 - RCE

Title source: llm

Description

snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/3116

Scores

EPSS 0.0979
EPSS Percentile 93.0%

Details

Status published
Products (2)
snews/snews 1.5.29
snews/snews 1.5.30
Published Jan 16, 2007
Tracked Since Feb 18, 2026