CVE-2004-2615 Information
Feb 14, 2021
cve
Description
The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions which allows local users to insert false news delete news and possibly gain privileges or have other unknown impact.
Reference
http://archives.neohapsis.com/archives/bugtraq/2004-08/0396.html http://securitytracker.com/id?1011099 http://www.osvdb.org/9385 https://exchange.xforce.ibmcloud.com/vulnerabilities/17161
Share on: