CVE detail
CVE-2007-5835 — CVE-2007-5835
Published 2007-11-05 · Modified 2026-06-16 · Vendor bosdev · Product bosnews · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0120
EPSS probability
exploitation probability, 30d
65.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References