VulnerabilityModified
CVE-2005-1876
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
MEDIUM 4.5EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
- CVSS 3.1
- 4.5 MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cutephp/cutenews
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111773528322711&w=2Third Party Advisory
- http://secunia.com/advisories/15594Broken Link
- http://www.osvdb.org/17030Broken Link
- http://marc.info/?l=bugtraq&m=111773528322711&w=2Third Party Advisory
- http://secunia.com/advisories/15594Broken Link
- http://www.osvdb.org/17030Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.