CutePHP

Short Name: [None Entered]
Previous Names: [None Entered]
URL: [None Entered]
Email: [None Entered]
Security URL: [None Entered]
Security Email: [None Entered]
Knowledge Base: [None Entered]
Notes: [No Notes]

Full Details...

Vulnerabilities by Vendor Product

CutePHP

CutePHP
CuteNews Watch-list
1.3
OSVDB ID: 2224 CuteNews Authenticated User index.php HTML Injection
OSVDB ID: 2880 CuteNews phpinfo Debug Information Disclosure
0.88
OSVDB ID: 5957 CuteNews shownews.php cutepath Variable Arbitrary Command Execution
OSVDB ID: 6052 CuteNews comments.php cutepath Variable Arbitrary Command Execution
OSVDB ID: 6051 CuteNews search.php cutepath Variable Arbitrary Command Execution
1.3.1
OSVDB ID: 7283 CuteNews show_archives.php id Parameter XSS
OSVDB ID: 7284 CuteNews show_news.php id Parameter XSS
OSVDB ID: 7286 CuteNews example2.php id Parameter XSS
OSVDB ID: 7285 CuteNews example1.php id Parameter XSS
OSVDB ID: 8833 CuteNews show_archives.php archive Parameter XSS
1.3.6
OSVDB ID: 9556 CuteNews show_archives.php cutepath Arbitrary Command Execution
OSVDB ID: 9557 CuteNews show_news.php cutepath Arbitrary Command Execution
OSVDB ID: 9385 CuteNews News.txt Weak Permission File Modification
OSVDB ID: 9558 CuteNews index.php mod Parameter XSS
1.4.0
OSVDB ID: 20474 CuteNews show_archives.php Remote Command Execution
OSVDB ID: 19478 CuteNews flood.db.php Client-IP HTTP Header Arbitrary Code Injection
1.4.1
OSVDB ID: 20474 CuteNews show_archives.php Remote Command Execution
OSVDB ID: 20473 CuteNews show_news.php template Parameter Traversal Arbitrary File Access
OSVDB ID: 23400 CuteNews show_news.php show Parameter XSS
OSVDB ID: 58827 CuteNews index.php Query String XSS
OSVDB ID: 20472 CuteNews show_archives.php template Parameter Traversal Arbitrary File Access
v1.4.5
OSVDB ID: 30659 CuteNews search.php XSS
OSVDB ID: 30658 CuteNews index.php Multiple Parameter XSS
1.4.5
OSVDB ID: 39888 CuteNews search.php files_arch Array Arbitrary File Access
1.3.1
OSVDB ID: 39888 CuteNews search.php files_arch Array Arbitrary File Access



The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use