Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.20137
Category:Web application abuses
Title:CuteNews directory traversal flaw
Summary:The version of CuteNews installed on the remote host fails to sanitize; user-supplied input to the 'template' parameter of the 'show_archives.php' and 'show_news.php' scripts.
Description:Summary:
The version of CuteNews installed on the remote host fails to sanitize
user-supplied input to the 'template' parameter of the 'show_archives.php' and 'show_news.php' scripts.

Vulnerability Impact:
An attacker can exploit this issue to read arbitrary files and possibly
even execute arbitrary PHP code on the remote host, subject to the privileges of the web server user id.

Solution:
Update to the latest version.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-3507
BugTraq ID: 15295
http://www.securityfocus.com/bid/15295
http://rgod.altervista.org/cute141.html
http://www.osvdb.org/20472
http://www.osvdb.org/20473
http://www.osvdb.org/20474
http://secunia.com/advisories/17435
http://www.vupen.com/english/advisories/2005/2296
CopyrightCopyright (C) 2005 David Maciejak

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.