CVE Vulnerabilities

CVE-2004-0660

Published: Aug 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.

Affected Software

NameVendorStart VersionEnd Version
CutenewsCutephp0.88 (including)0.88 (including)
CutenewsCutephp1.3 (including)1.3 (including)
CutenewsCutephp1.3.1 (including)1.3.1 (including)

References