CVE-2009-4115
Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the (1) category and…
Does this matter?
Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the (1) category and (2) Icon URL fields; or (3) inject arbitrary PHP code into data/ipban.php via the add_ip parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cutephp/cutenews
- Source
- cve@mitre.org
References
- http://www.morningstarsecurity.com/advisories/MORNINGSTAR-2009-02-CuteNews.txtExploit
- http://www.securityfocus.com/archive/1/507782/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54243
- http://www.morningstarsecurity.com/advisories/MORNINGSTAR-2009-02-CuteNews.txtExploit
- http://www.securityfocus.com/archive/1/507782/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54243
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.