PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.
References
Link | Resource |
---|---|
http://seclists.org/lists/bugtraq/2004/Sep/0014.html | Exploit Vendor Advisory |
http://secunia.com/advisories/12432 | Exploit Vendor Advisory |
http://www.7a69ezine.org/node/view/130 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17288 | |
http://seclists.org/lists/bugtraq/2004/Sep/0014.html | Exploit Vendor Advisory |
http://secunia.com/advisories/12432 | Exploit Vendor Advisory |
http://www.7a69ezine.org/node/view/130 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17288 |
Configurations
History
20 Nov 2024, 23:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/lists/bugtraq/2004/Sep/0014.html - Exploit, Vendor Advisory | |
References | () http://secunia.com/advisories/12432 - Exploit, Vendor Advisory | |
References | () http://www.7a69ezine.org/node/view/130 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17288 - |
Information
Published : 2004-08-30 04:00
Updated : 2024-11-20 23:51
NVD link : CVE-2004-1660
Mitre link : CVE-2004-1660
CVE.ORG link : CVE-2004-1660
JSON object : View
Products Affected
cutephp
- cutenews
CWE