Back

MEDIUM

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file

Published Jun 7, 2005

Description

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 7, 2005
Updated Jan 16, 2025
Reserved Jun 8, 2005
CISA Vulnrichment
Updated Feb 14, 2024
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a