{"api_version":"1","generated_at":"2026-07-23T11:04:52+00:00","cve":"CVE-2007-0261","urls":{"html":"https://cve.report/CVE-2007-0261","api":"https://cve.report/api/cve/CVE-2007-0261.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0261","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0261"},"summary":{"title":"CVE-2007-0261","description":"snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-16 23:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/22025","name":"http://www.securityfocus.com/bid/22025","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"sNews SNews.PHP Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/32817","name":"http://osvdb.org/32817","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/23746","name":"http://secunia.com/advisories/23746","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"sNews Authentication Bypass Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/3116","name":"https://www.exploit-db.com/exploits/3116","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"sNews <= 1.5.30 Remote Reset Admin Pass / Command Exec Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31535","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31535","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0261","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0261","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"261","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"snews","cpe5":"snews","cpe6":"1.5.29","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"261","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"snews","cpe5":"snews","cpe6":"1.5.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:17.838Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"snews-image-file-upload(31535)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31535"},{"name":"22025","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22025"},{"name":"23746","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23746"},{"name":"3116","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/3116"},{"name":"32817","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32817"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"snews-image-file-upload(31535)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31535"},{"name":"22025","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22025"},{"name":"23746","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23746"},{"name":"3116","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/3116"},{"name":"32817","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32817"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0261","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"snews-image-file-upload(31535)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31535"},{"name":"22025","refsource":"BID","url":"http://www.securityfocus.com/bid/22025"},{"name":"23746","refsource":"SECUNIA","url":"http://secunia.com/advisories/23746"},{"name":"3116","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/3116"},{"name":"32817","refsource":"OSVDB","url":"http://osvdb.org/32817"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0261","datePublished":"2007-01-16T23:00:00.000Z","dateReserved":"2007-01-16T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:17.838Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-16 23:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:snews:snews:1.5.29:*:*:*:*:*:*:*","matchCriteriaId":"2CDD2160-EFDD-487B-A896-CD0A270F54C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:snews:snews:1.5.30:*:*:*:*:*:*:*","matchCriteriaId":"92B2732D-7DE1-4549-8811-8B7A0ACC5509"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"261","Ordinal":"1","Title":"CVE-2007-0261","CVE":"CVE-2007-0261","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"261","Ordinal":"1","NoteData":"snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.","Type":"Description","Title":"CVE-2007-0261"},{"CveYear":"2007","CveId":"261","Ordinal":"2","NoteData":"2007-01-16","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"261","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}