CVE-2006-1925
- EPSS 0.53%
- Veröffentlicht 20.04.2006 18:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also pro...
- EPSS 0.48%
- Veröffentlicht 21.03.2006 02:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
- EPSS 1.94%
- Veröffentlicht 21.03.2006 02:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in...
CVE-2006-1121
- EPSS 7.04%
- Veröffentlicht 09.03.2006 21:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.
CVE-2006-0885
- EPSS 0.7%
- Veröffentlicht 25.02.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.
- EPSS 0.35%
- Veröffentlicht 16.11.2005 07:42:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.
- EPSS 5.83%
- Veröffentlicht 06.11.2005 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
CVE-2005-3010
- EPSS 2.43%
- Veröffentlicht 21.09.2005 20:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data...
CVE-2005-3009
- EPSS 0.34%
- Veröffentlicht 21.09.2005 20:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.
- EPSS 0.41%
- Veröffentlicht 27.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.