Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801056
Category:Web application abuses
Title:CuteNews/UTF-8 CuteNews Multiple Vulnerabilities
Summary:CuteNews/UTF-8 CuteNews is prone to multiple vulnerabilities.
Description:Summary:
CuteNews/UTF-8 CuteNews is prone to multiple vulnerabilities.

Vulnerability Insight:
- An improper validation of user-supplied input by the 'category.db.php'
script via the Category Access field or Icon URL fields

- An improper validation of user-supplied input by the 'data/ipban.php' script via the add_ip parameter.

- An improper validation of user-supplied input by the 'Editnews module' via list or editnews parameters and
'Options module' via save_con[skin] parameter.

- An error in 'editusers' module within 'index.php' allows attackers to hijack the authentication of
administrators for requests that create new users.

- An error in 'from_date_day' parameter to 'search.php' which reveals the installation path in an error message.

- An error in 'modified id' parameter in a 'doeditnews' action allows remote users with Journalist or Editor
access to bypass administrative moderation and edit previously submitted articles.

- An improper validation of user-supplied input by the result parameter to 'register.php', the user parameter to
'search.php', the cat_msg, source_msg, postponed_selected, unapproved_selected, and news_per_page parameters in a
list action to the editnews module of 'index.php' and the link tag in news comments

- An error in lastusername and mod parameters to 'index.php' and the title parameter to 'search.php' it allow
attackers to inject arbitrary web script or HTML

Vulnerability Impact:
Successful exploitation could allow remote attackers to steal user
credentials, disclose file contents, disclose the file path of the application, execute arbitrary commands.

Affected Software/OS:
CuteNews version 1.4.6 and UTF-8 CuteNews version prior to 8b.

Solution:
For UTF-8 CuteNews Upgrade to version 8b or later.

For CuteNews Upgrade to version 1.5.0.1 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-4113
Bugtraq: 20091110 [MORNINGSTAR-2009-02] Multiple security issues in Cute News and UTF-8 Cute News (Google Search)
http://www.securityfocus.com/archive/1/507782/100/0/threaded
http://www.morningstarsecurity.com/advisories/MORNINGSTAR-2009-02-CuteNews.txt
XForce ISS Database: cutenews-categories-code-execution(54243)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54243
Common Vulnerability Exposure (CVE) ID: CVE-2009-4116
XForce ISS Database: cutenews-editnews-dir-traversal(54246)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54246
XForce ISS Database: cutenews-options-file-include(54244)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54244
Common Vulnerability Exposure (CVE) ID: CVE-2009-4115
Common Vulnerability Exposure (CVE) ID: CVE-2009-4174
BugTraq ID: 36971
http://www.securityfocus.com/bid/36971
XForce ISS Database: cutenews-articles-security-bypass(54236)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54236
Common Vulnerability Exposure (CVE) ID: CVE-2009-4175
XForce ISS Database: cutenews-search-path-disclosure(54235)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54235
Common Vulnerability Exposure (CVE) ID: CVE-2009-4173
XForce ISS Database: cutenews-index-csrf(54240)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54240
Common Vulnerability Exposure (CVE) ID: CVE-2009-4172
XForce ISS Database: cutenews-newsarticles-xss(54225)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54225
Common Vulnerability Exposure (CVE) ID: CVE-2009-4250
XForce ISS Database: cutenews-editnews-xss(54223)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54223
XForce ISS Database: cutenews-newscomments-xss(54224)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54224
XForce ISS Database: cutenews-register-xss(54221)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54221
XForce ISS Database: cutenews-search-xss(54222)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54222
XForce ISS Database: cutenews-title-xss(54237)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54237
Common Vulnerability Exposure (CVE) ID: CVE-2009-4249
XForce ISS Database: cutenews-index-xss(54220)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54220
XForce ISS Database: cutenews-lastusername-xss(54219)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54219
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.