CVE Vulnerabilities

CVE-2004-2615

Published: Dec 31, 2004 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

Affected Software

Name Vendor Start Version End Version
Cutenews Cutephp 1.3.6 (including) 1.3.6 (including)

References