Critical severity9.8NVD Advisory· Published Apr 4, 2026· Updated Apr 14, 2026
CVE-2016-20052
CVE-2016-20052
Description
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/40706nvdExploitVDB Entry
- www.vulncheck.com/advisories/snews-cms-unrestricted-file-upload-via-snews-filesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.