Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
References
Configurations
Information
Published : 2005-06-08 21:00
Updated : 2016-10-17 20:23
NVD link : CVE-2005-1876
Mitre link : CVE-2005-1876
JSON object : View
CWE
Products Affected
cutephp
- cutenews