plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.
References
Configurations
History
21 Nov 2024, 00:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/28330 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/4403 - | |
References | () http://www.osvdb.org/40236 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/39450 - | |
References | () https://www.exploit-db.com/exploits/4851 - |
Information
Published : 2008-10-14 22:36
Updated : 2024-11-21 00:51
NVD link : CVE-2008-4557
Mitre link : CVE-2008-4557
CVE.ORG link : CVE-2008-4557
JSON object : View
Products Affected
cutephp
- cutenews
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')