plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.
References
Configurations
Information
Published : 2008-10-14 15:36
Updated : 2017-09-28 18:32
NVD link : CVE-2008-4557
Mitre link : CVE-2008-4557
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
cutephp
- cutenews