CVE Vulnerabilities

CVE-2006-4445

Published: Aug 29, 2006 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter to (1) show_news.php or (2) search.php. NOTE: CVE analysis as of 20060829 has not identified any scenarios in which these vectors could result in remote file inclusion

Affected Software

Name Vendor Start Version End Version
Cutenews Cutephp 1.3 (including) 1.3 (including)
Cutenews Cutephp 1.3.1 (including) 1.3.1 (including)
Cutenews Cutephp 1.3.2 (including) 1.3.2 (including)
Cutenews Cutephp 1.3.6 (including) 1.3.6 (including)

References