Description
The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2004-2606 | The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T01:36:24.225Z
Reserved: 2005-12-04T00:00:00.000Z
Link: CVE-2004-2615
No data.
Status : Modified
Published: 2004-12-31T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-2615
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD