Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111773528322711&w=2 | Third Party Advisory |
http://secunia.com/advisories/15594 | Broken Link |
http://www.osvdb.org/17030 | Broken Link |
Configurations
History
No history.
Information
Published : 2005-06-09 04:00
Updated : 2024-02-13 16:19
NVD link : CVE-2005-1876
Mitre link : CVE-2005-1876
CVE.ORG link : CVE-2005-1876
JSON object : View
Products Affected
cutephp
- cutenews
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')