PT-2005-3847 · Cutenews · Cutenews

Rgod

·

Published

2005-09-21

·

Updated

2008-09-05

·

CVE-2005-3010

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CuteNews versions 1.4.0 and earlier
Description A direct static code injection issue exists in the flood protection feature of CuteNews, allowing remote attackers to execute arbitrary PHP code. This is achieved by injecting malicious code via the HTTP CLIENT IP header, which is then inserted into data/flood.db.php.
Recommendations For CuteNews versions 1.4.0 and earlier, consider disabling the flood protection feature in inc/shows.inc.php until a patch is available to prevent exploitation. Restrict access to data/flood.db.php to minimize the risk of arbitrary PHP code execution. Avoid using the HTTP CLIENT IP header in the affected feature until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3010

Affected Products

Cutenews