plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.
References
Configurations
History
No history.
Information
Published : 2008-10-14 22:36
Updated : 2024-02-04 17:33
NVD link : CVE-2008-4557
Mitre link : CVE-2008-4557
CVE.ORG link : CVE-2008-4557
JSON object : View
Products Affected
cutephp
- cutenews
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')