Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown

CVE-2020-5558

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
Attacker Value
Unknown

CVE-2020-5557

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2019-11447

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
0
Attacker Value
Unknown

CVE-2009-4250

Disclosure Date: December 10, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to register.php; (2) the user parameter to search.php; the (3) cat_msg, (4) source_msg, (5) postponed_selected, (6) unapproved_selected, and (7) news_per_page parameters in a list action to the editnews module of index.php; and (8) the link tag in news comments. NOTE: some of the vulnerabilities require register_globals to be enabled and/or magic_quotes_gpc to be disabled.
0
Attacker Value
Unknown

CVE-2009-4249

Disclosure Date: December 10, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters to index.php; and (3) the title parameter to search.php.
0
Attacker Value
Unknown

CVE-2009-4174

Disclosure Date: December 02, 2009 (last updated October 04, 2023)
The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.
0
Attacker Value
Unknown

CVE-2009-4173

Disclosure Date: December 02, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for requests that create new users, including a new administrator, via an adduser action in the editusers module in index.php.
0
Attacker Value
Unknown

CVE-2009-4172

Disclosure Date: December 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the body of a news article in an addnews action.
0
Attacker Value
Unknown

CVE-2009-4175

Disclosure Date: December 02, 2009 (last updated October 04, 2023)
CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2009-4113

Disclosure Date: November 30, 2009 (last updated October 04, 2023)
Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the Category Access field.
0