7.5
CVSSv2

CVE-2005-3010

Published: 21/09/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and previous versions allows remote malicious users to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cutephp cutenews

Exploits

<?php # cutenxplphp # # # # CuteNews 140(possibly prior versions) remote code execution # # by rgod # # ...