CVE-2008-4203

Czaries Czarnews < 1.20 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.

Exploits (2)

exploitdb WORKING POC VERIFIED
by 0ut0fbound · textwebappsphp
https://www.exploit-db.com/exploits/6464
exploitdb WORKING POC VERIFIED
by StAkeR · perlwebappsphp
https://www.exploit-db.com/exploits/6462

Scores

EPSS 0.0030
EPSS Percentile 53.7%

Details

CWE
CWE-89
Status published
Products (4)
czaries/czarnews 1.12
czaries/czarnews 1.13 (2 CPE variants)
czaries/czarnews 1.14
czaries/czarnews < 1.20
Published Sep 24, 2008
Tracked Since Feb 18, 2026