CVE-2008-4203
Czaries Czarnews < 1.20 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by 0ut0fbound · textwebappsphp
https://www.exploit-db.com/exploits/6464
Scores
EPSS
0.0030
EPSS Percentile
53.7%
Details
CWE
CWE-89
Status
published
Products (4)
czaries/czarnews
1.12
czaries/czarnews
1.13 (2 CPE variants)
czaries/czarnews
1.14
czaries/czarnews
< 1.20
Published
Sep 24, 2008
Tracked Since
Feb 18, 2026