


Perceptive Security
SOC/SIEM Consultancy

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to th…
Published:
3 april 2026 om 22:00:00
Alert date:
4 april 2026 om 15:05:07
Source:
nvd.nist.gov
Web Technologies
CVE-2016-20052 is an unrestricted file upload vulnerability in Snews CMS version 1.7 that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can exploit this vulnerability through the multipart form-data upload endpoint to upload malicious PHP files. Once uploaded, attackers can execute these files by accessing the uploaded file path, leading to remote code execution. This vulnerability poses a significant security risk as it requires no authentication and can result in complete system compromise. The vulnerability has been documented with proof-of-concept exploits available on Exploit-DB.
Technical details
Mitigation steps:
Affected products:
Snews CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2016-20052
https://www.exploit-db.com/exploits/40706
https://www.vulncheck.com/advisories/snews-cms-unrestricted-file-upload-via-snews-files
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
