Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111773528322711&w=2 | Third Party Advisory |
http://secunia.com/advisories/15594 | Broken Link |
http://www.osvdb.org/17030 | Broken Link |
Configurations
History
13 Feb 2024, 16:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=111773528322711&w=2 - Third Party Advisory | |
References | () http://secunia.com/advisories/15594 - Broken Link | |
References | () http://www.osvdb.org/17030 - Broken Link | |
CWE | CWE-94 | |
CPE | cpe:2.3:a:cutephp:cutenews:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 4.4
v3 : unknown |
Information
Published : 2005-06-09 04:00
Updated : 2024-02-13 16:19
NVD link : CVE-2005-1876
Mitre link : CVE-2005-1876
CVE.ORG link : CVE-2005-1876
JSON object : View
Products Affected
cutephp
- cutenews
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')