PT-2005-2833 · Cutenews · Cutenews

John Cantu

·

Publicado

2005-06-07

·

Atualizado

2025-01-16

·

CVE-2005-1876

CVSS v3.1

4.5

Média

VetorAV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CuteNews versions 1.3.6 and earlier
Description A direct code injection issue allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
Recommendations For CuteNews versions 1.3.6 and earlier, consider restricting access to administrative privileges and limiting the ability to inject code into template files until a fix is available. As a temporary workaround, consider disabling the template editing feature for users with administrative privileges to minimize the risk of exploitation.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-1876

Produtos afetados

Cutenews