CVE-2010-2926

sNews 1.7 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by CoBRa_21 · textwebappsphp
https://www.exploit-db.com/exploits/14465

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14465
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/60622

Scores

EPSS 0.0010
EPSS Percentile 27.8%

Details

CWE
CWE-89
Status published
Products (1)
solucija/snews 1.7
Published Jul 30, 2010
Tracked Since Feb 18, 2026