![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2006-1925 |
Description: | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-1925 BugTraq ID: 17592 http://www.securityfocus.com/bid/17592 Bugtraq: 20060418 CuteNews 1.4.1 <= Cross Site Scripting (Google Search) http://www.securityfocus.com/archive/1/431340/30/0/threaded Bugtraq: 20060420 Re: CuteNews 1.4.1 <= Cross Site Scripting (Google Search) http://www.securityfocus.com/archive/1/431528/100/0/threaded http://securityreason.com/securityalert/775 XForce ISS Database: cutenews-index-source-xss(25935) https://exchange.xforce.ibmcloud.com/vulnerabilities/25935 |