Beveiligingsadvies

CVE-2005-1876

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2005-06-07 04:00:00
Laatst bijgewerkt 2025-01-16 19:13:11
Toegewezen door mitre
CVSS-score 4.5
Status PUBLISHED

Beschrijving

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.