CVE-2003-1240 Information

Description

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php (2) search.php or (3) comments.php.

Reference

http://archives.neohapsis.com/archives/bugtraq/2003-02/0320.html http://www.iss.net/security_center/static/11417.php http://www.securityfocus.com/bid/6935

Share on: