CVE-2008-0723

Planetluc Mynews < 1.6.4 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SkyOut · textwebappsphp
https://www.exploit-db.com/exploits/31115

Scores

EPSS 0.0037
EPSS Percentile 58.2%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

planetluc/mynews < 1.6.4

Timeline

Published Feb 12, 2008
Tracked Since Feb 18, 2026