CVE-2007-3136

newsSync 1.5.0rc6 - Code Injection

Title source: llm

Description

PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL in the newsSync_NUKE_PATH parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by GoLd_M · htmlwebappsphp
https://www.exploit-db.com/exploits/4041

Scores

EPSS 0.0534
EPSS Percentile 90.1%

Details

Status published
Products (1)
newssync/newssync 1.5.0_rc6
Published Jun 08, 2007
Tracked Since Feb 18, 2026