CVE-2007-6082

Sciurus Hosting Panel - Code Injection

Title source: llm

Description

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Liz0ziM · phpwebappsphp
https://www.exploit-db.com/exploits/4635

Scores

EPSS 0.0825
EPSS Percentile 92.2%

Details

CWE
CWE-94
Status published
Products (1)
sciurus/sciurus_hosting_panel 2.0.3
Published Nov 22, 2007
Tracked Since Feb 18, 2026