Vulnerabilities > CVE-2007-0261 - Authentication Bypass vulnerability in Snews 1.5.29/1.5.30

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
snews
critical
exploit available

Summary

snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.

Vulnerable Configurations

Part Description Count
Application
Snews
2

Exploit-Db

descriptionsNews <= 1.5.30 Remote Reset Admin Pass / Command Exec Exploit. CVE-2007-0261. Webapps exploit for php platform
fileexploits/php/webapps/3116.php
idEDB-ID:3116
last seen2016-01-31
modified2007-01-12
platformphp
port
published2007-01-12
reporterrgod
sourcehttps://www.exploit-db.com/download/3116/
titlesNews <= 1.5.30 - Remote Reset Admin Pass / Command Exec Exploit
typewebapps