Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-5558 CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. Cutenews No fix yet Fix from $1,9502020-03-25 MEDIUM 6.1 CVE-2020-5557 Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Cutenews Mitigation only Fix from $1,6002020-03-25 HIGH 8.8 CVE-2019-11447EPSS 52% An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via th… Cutenews No fix yet Fix from $1,9502019-04-22 MEDIUM 6.8 CVE-2009-4173 Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authenti… Cutenews No fix yet Fix from $1,6002009-12-02 MEDIUM 6.0 CVE-2009-4174 The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with… Cutenews No fix yet Fix from $1,6002009-12-02 MEDIUM 5.0 CVE-2009-4175 CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_dat… Cutenews No fix yet Fix from $1,6002009-12-02 MEDIUM 6.5 CVE-2009-4113 Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users… Cutenews No fix yet Fix from $1,6002009-11-30 MEDIUM 6.5 CVE-2009-4115 Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application a… Cutenews No fix yet Fix from $1,6002009-11-30 HIGH 10.0 CVE-2008-4557EPSS 45% plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the te… Cutenews No fix yet Fix from $1,9502008-10-14 MEDIUM 5.8 CVE-2007-6662 Directory traversal vulnerability in file.php in CuteNews 2.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file paramete… Cutenews Mitigation only Fix from $1,6002008-01-04 HIGH 7.5 CVE-2007-1153 Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vec… Cutenews Mitigation only Fix from $1,9502007-03-02 HIGH 7.5 CVE-2006-4445 Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath p… Cutenews Mitigation only Fix from $1,9502006-08-29 MEDIUM 6.4 CVE-2006-2250 CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, w… Cutenews Mitigation only Fix from $1,6002006-05-09 MEDIUM 5.0 CVE-2006-1339 Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows re… Cutenews after 1.4.1 Fix from $1,6002006-03-21 MEDIUM 5.0 CVE-2006-1340 CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file … Cutenews after 1.4.1 Fix from $1,6002006-03-21 MEDIUM 6.8 CVE-2006-1121 Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to ind… Cutenews No fix yet Fix from $1,6002006-03-09 MEDIUM 5.0 CVE-2005-3592 index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error me… Cutenews after 1.4.0 Fix from $1,6002005-11-16 MEDIUM 5.0 CVE-2005-3507EPSS 12% Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" s… Cutenews after 1.4.1 Fix from $1,6002005-11-06 HIGH 7.5 CVE-2005-3010EPSS 6% Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers… Cutenews after 1.4.0 Fix from $1,9502005-09-21 MEDIUM 5.0 CVE-2005-2394 show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter. Cutenews No fix yet Fix from $1,6002005-07-27 HIGH 7.5 CVE-2004-1660 PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath paramete… Cutenews after 1.3.6 Fix from $1,9502004-08-30 MEDIUM 6.8 CVE-2004-0660 Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote at… Cutenews Mitigation only Fix from $1,6002004-08-06 HIGH 7.5 CVE-2003-1240EPSS 7% PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in… Cutenews No fix yet Fix from $1,9502003-12-31