5
CVSSv2

CVE-2005-3507

Published: 06/11/2005 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in CuteNews 1.4.1 allows remote malicious users to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cutephp cutenews

Exploits

source: wwwsecurityfocuscom/bid/15295/info CuteNews is affected by a directory traversal vulnerability An unauthorized attacker can retrieve or upload arbitrary files by supplying directory traversal strings '/' through an affected URI parameter Exploitation of this vulnerability could lead to a loss of confidentiality as arbitra ...
source: wwwsecurityfocuscom/bid/15295/info CuteNews is affected by a directory traversal vulnerability An unauthorized attacker can retrieve or upload arbitrary files by supplying directory traversal strings '/' through an affected URI parameter Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary ...