CVE-2007-0261
Published Jan 16, 2007
Last updated 7 years ago
Overview
- Description
- snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:snews:snews:1.5.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2CDD2160-EFDD-487B-A896-CD0A270F54C6" }, { "criteria": "cpe:2.3:a:snews:snews:1.5.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92B2732D-7DE1-4549-8811-8B7A0ACC5509" } ], "operator": "OR" } ] } ]