CVE-2005-1876 Information

Description

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

Reference

http://marc.info/?l=bugtraq&m=111773528322711&w=2 http://secunia.com/advisories/15594 http://www.osvdb.org/17030

Share on: