Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cutenews HIGH 8.8
CVE-2020-5558

CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.

No fix yet
Fix from $1,950 2020-03-25
Cutenews MEDIUM 6.1
CVE-2020-5557

Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Mitigation only
Fix from $1,600 2020-03-25
Cutenews HIGH 8.8
CVE-2019-11447EPSS 52%

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via th…

No fix yet
Fix from $1,950 2019-04-22
Cutenews MEDIUM 6.8
CVE-2009-4173

Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authenti…

No fix yet
Fix from $1,600 2009-12-02
Cutenews MEDIUM 6.0
CVE-2009-4174

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with…

No fix yet
Fix from $1,600 2009-12-02
Cutenews MEDIUM 5.0
CVE-2009-4175

CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_dat…

No fix yet
Fix from $1,600 2009-12-02
Cutenews MEDIUM 6.5
CVE-2009-4113

Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users…

No fix yet
Fix from $1,600 2009-11-30
Cutenews MEDIUM 6.5
CVE-2009-4115

Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application a…

No fix yet
Fix from $1,600 2009-11-30
Cutenews HIGH 10.0
CVE-2008-4557EPSS 45%

plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the te…

No fix yet
Fix from $1,950 2008-10-14
Cutenews MEDIUM 5.8
CVE-2007-6662

Directory traversal vulnerability in file.php in CuteNews 2.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file paramete…

Mitigation only
Fix from $1,600 2008-01-04
Cutenews HIGH 7.5
CVE-2007-1153

Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vec…

Mitigation only
Fix from $1,950 2007-03-02
Cutenews HIGH 7.5
CVE-2006-4445

Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath p…

Mitigation only
Fix from $1,950 2006-08-29
Cutenews MEDIUM 6.4
CVE-2006-2250

CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, w…

Mitigation only
Fix from $1,600 2006-05-09
Cutenews MEDIUM 6.8
CVE-2006-1121

Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to ind…

No fix yet
Fix from $1,600 2006-03-09
Cutenews MEDIUM 5.0
CVE-2005-2394

show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.

No fix yet
Fix from $1,600 2005-07-27
Cutenews MEDIUM 6.8
CVE-2004-0660

Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote at…

Mitigation only
Fix from $1,600 2004-08-06
Cutenews HIGH 7.5
CVE-2003-1240EPSS 7%

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in…

No fix yet
Fix from $1,950 2003-12-31