CVE-2007-0261
Last modified
CVE-2007-0261 is a vulnerability of currently unknown severity. snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.. EPSS estimates a 4.52% chance of exploitation in the next 30 days.
Description
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Snews | Snews | 1.5.29 |
| Snews | Snews | 1.5.30 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0261?
How severe is CVE-2007-0261?
How do I fix CVE-2007-0261?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0255XINE 0.99.4 allows user-assisted remote attackers to cause a…
- CVE-2007-0256VideoLAN VLC 0.8.6a allows remote attackers to cause a denia…
- CVE-2007-0257Unspecified vulnerability in the expand_stack function in gr…7.8
- CVE-2007-0258Cross-site scripting (XSS) vulnerability in index.php in (1)…
- CVE-2007-0259Ezboxx Portal System Beta 0.7.6 and earlier allows remote at…
- CVE-2007-0260PHP remote file inclusion vulnerability in index.php in Naig…
- CVE-2007-0262WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properl…
- CVE-2007-0263Unspecified vulnerability in Total Commander before 6.5.6 al…
- CVE-2007-0264Buffer overflow in Winzip32.exe in WinZip 9.0 allows local u…
- CVE-2007-0265Multiple cross-site scripting (XSS) vulnerabilities in Ezbox…
- CVE-2007-0266SQL injection vulnerability in boxx/ShowAppendix.asp in Ezbo…
- CVE-2007-0267The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6…
Are you affected by CVE-2007-0261?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
