Description
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 16 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-16T19:13:11.881Z
Reserved: 2005-06-08T00:00:00.000Z
Link: CVE-2005-1876
Updated: 2024-08-07T22:06:57.133Z
Status : Modified
Published: 2005-06-09T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2005-1876
No data.
OpenCVE Enrichment
No data.
Weaknesses