Vulnerabilities > Phnews

DATE CVE VULNERABILITY TITLE RISK
2009-03-10 CVE-2009-0866 Permissions, Privileges, and Access Controls vulnerability in Phnews 1
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for extra/genbackup.php.
network
low complexity
phnews CWE-264
5.0