Skip to main content

Vendor/product archive

cutephp / cutenews CVEs

Beta · best-effort

39 CVEs tagged to cutephp / cutenews1 Critical, 8 High, 26 Medium, 4 Low, 0 Unrated.

CVE-2020-5558

Published Mar 25, 2020

CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5557

Published Mar 25, 2020

Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11447

Published Apr 22, 2019

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4250

Published Dec 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to inject arbitrary web script or HTML via (1) th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4249

Published Dec 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4175

Published Dec 2, 2009

CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4174

Published Dec 2, 2009

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4173

Published Dec 2, 2009

Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4172

Published Dec 2, 2009

Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is disabled, allows remote attackers to inject a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4116

Published Nov 30, 2009

Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authenticated users with editor or administrative applicati…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4115

Published Nov 30, 2009

Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4113

Published Nov 30, 2009

Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4557

Published Oct 14, 2008

plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserte…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6662

Published Jan 4, 2008

Directory traversal vulnerability in file.php in CuteNews 2.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1153

Published Mar 2, 2007

Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the provenance of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6300

Published Dec 5, 2006

Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4445

Published Aug 29, 2006

Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter to (1) show_news.php…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3661

Published Jul 18, 2006

Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance o…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2249

Published May 9, 2006

Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2250

Published May 9, 2006

CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an err…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1925

Published Apr 20, 2006

Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1339

Published Mar 21, 2006

Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1340

Published Mar 21, 2006

CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1121

Published Mar 9, 2006

Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0885

Published Feb 25, 2006

Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2